Port 324RPKI Router Protocol over TLS

Encrypted RPKI Router Protocol sessions used by routers to retrieve validated route-origin data from RPKI cache servers.

transport
tcp

single transport

in transit
encrypted

payload protected on the wire

assignment
official

registered with iana

risk
2/10

safe

lookups
0

rank 994 of 3,489 · top 28%

also known as rpki-rtr-tls, RPKI-RTR over TLS, RTR over TLS

Technical Details

what runs on :324

The client establishes a TCP connection to port 324 and completes a TLS handshake before exchanging binary RPKI-RTR protocol data. RTR uses framed PDUs carrying session, serial-query, reset, and validated-prefix information; routers use these exchanges to synchronize a cache's current or incremental routing-validation state. TCP 323 is the commonly assigned non-TLS RTR port, while TCP 324 identifies the TLS transport.

Security Information

exposure of :324

risk score

2/ 10safe

routine exposure. this port is rarely the way in on its own — keep it patched and logged and move on.

security averages 3.2 across 326 ports — this one sits 1.2 below.

in transit

encrypted

payloads are protected on the wire

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

TLS provides confidentiality and integrity for the RTR exchange, and deployments should validate the configured cache server's identity and restrict which caches routers trust. The service exposes routing-validation data rather than general router administration, but an exposed or misconfigured cache endpoint can enable denial of service or delivery of untrusted data; internet reachability may be intentional for public RPKI caches.

the 8 most looked-up other ports in security — 326 ports carry that label.

risk mix of the 8 listed

  • caution100%

3 of 8 encrypted