Port 2944Megaco H.248

Megaco H.248, also known as H.248 or Megaco Text, is a protocol that manages multimedia communication sessions between media gateways and media gateway controllers within next-generation networks, often used in Voice over IP (VoIP) architectures. It enables signaling and control functions essential for voice, video, and data transfer across various communication networks..

transport
udp

single transport

in transit
cleartext

payload readable on path

assignment
unofficial

used by convention

risk
4/10

caution

lookups
8,155

rank 619 of 993 · top 62%

Technical Details

what runs on :2944

Megaco, standardized as H.248 by ITU-T, is a protocol primarily designed to control media gateways on Internet Protocol (IP) networks and the public switched telephone network (PSTN). It separates the call control functions handled by media gateway controllers from the media conversion tasks performed by media gateways. The protocol enables flexible service deployment, interoperability between vendors, and scalability of large VoIP networks.

Megaco supports a text-based message encoding (port 2944) and a binary ASN.1 encoding (typically on port 2945). The text version is human-readable, facilitating troubleshooting and debugging, albeit with some additional bandwidth overhead. Through commands, responses, and notifications, Megaco defines operations such as setting up and tearing down calls, managing media streams, and controlling media resources like tones and announcements.

This protocol is typically deployed in softswitch architectures, carrier-grade VoIP, and broadband telephony services. It communicates user actions, network events, and media status, enabling seamless call control integration across multi-vendor network components, which is crucial in modern converged voice-data infrastructures.

Security Information

exposure of :2944

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

unofficial

used by convention, not registered — what answers here varies by deployment

reachable over

udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common Vulnerabilities:

  • Lack of encryption can lead to eavesdropping and interception of control commands.
  • Poor input validation may expose gateways to denial-of-service (DoS) attacks through malformed messages.
  • Unauthorized access to gateways can facilitate call interception or service disruption.
  • Man-in-the-middle attacks might alter signaling, causing fraud or call rerouting.

Common Mitigations:

  • Employ network segmentation and strict firewall rules, allowing UDP traffic on port 2944 only between authorized devices.
  • Enforce authentication and access controls on devices utilizing Megaco H.248.
  • Monitor signaling traffic for anomalies or unauthorized message patterns.
  • Where technically feasible, deploy VPNs or other encrypted tunnels to protect signaling paths.
  • Keep firmware on media gateways and controllers current to patch known vulnerabilities.

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted