Port 3121Pacemaker Remote

Pacemaker Remote uses TCP 3121 to let a Pacemaker cluster manage resources on remote nodes.

transport
tcp

single transport

in transit
encrypted

payload protected on the wire

assignment
official

registered with iana

risk
6/10

risk

lookups
0

rank 994 of 3,137 · top 32%

also known as pcmk-remote, pacemaker-remoted

Technical Details

what runs on :3121

The service uses TCP port 3121 and normally begins with a TLS-protected, mutually authenticated connection using Pacemaker authentication credentials, commonly a shared authkey. After the connection is established, the cluster uses the Pacemaker Remote protocol to proxy resource-management operations to the remote node; it is not an interactive SSH service. The port is distinct from Pacemaker administration services such as pcsd, commonly associated with TCP 2224, and from the cluster communication ports used by Corosync.

Security Information

exposure of :3121

risk score

6/ 10risk

treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.

remote access averages 3.7 across 167 ports — this one sits 2.3 above.

in transit

encrypted

payloads are protected on the wire

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

Pacemaker Remote provides authenticated remote resource-management access and should be restricted to the cluster nodes or management network with firewall rules. Do not expose TCP 3121 directly to the Internet: compromise of authentication material or the remote daemon could let an attacker execute or control cluster-managed resource operations on the host.

the 8 most looked-up other ports in remote access — 167 ports carry that label.

risk mix of the 8 listed

  • safe13%
  • caution88%

0 of 8 encrypted