Port 3130Internet Cache Protocol v2

ICPv2 lets web-cache proxies query peer caches about whether they have a requested object.

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
2/10

safe

lookups
0

rank 993 of 4,503 · top 22%

also known as icpv2, ICP

Technical Details

what runs on :3130

ICPv2 (Internet Cache Protocol version 2, RFC 2186) coordinates web-cache hierarchies. A cache sends a query containing a URL to a peer and receives a response such as HIT or MISS; messages are compact and carry an opcode, request identifier, and URL. The protocol has no connection handshake and is conventionally sent as UDP datagrams on port 3130. IANA lists both TCP and UDP, but ordinary ICPv2 deployments use UDP. Squid commonly uses 3130 for ICP; this is separate from the HTTP proxy listener, often on port 3128.

Security Information

exposure of :3130

risk score

2/ 10safe

routine exposure. this port is rarely the way in on its own — keep it patched and logged and move on.

web services averages 3.2 across 183 ports — this one sits 1.2 below.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

ICPv2 is unencrypted and does not authenticate peers, so cache operators should allow it only between explicitly trusted cache hosts, not expose it broadly to the internet. Unrestricted access can reveal cache-hit information and consume proxy resources; unauthenticated UDP also makes spoofed messages possible. It is cache-coordination traffic rather than a service intended for public clients.

the 8 most looked-up other ports in web services — 183 ports carry that label.

risk mix of the 8 listed

  • safe13%
  • caution88%

0 of 8 encrypted