Port 3478STUN / TURN
STUN and TURN commonly use port 3478 for NAT discovery and relaying; the IANA handle specifically denotes STUN behavior discovery over TCP.
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 0
2 transports registered
payload readable on path
registered with iana
caution
rank 993 of 4,715 · top 21%
also known as stun-behavior, RFC 5780
2 other services are registered on port 3478. compare all 3 →
Technical Details
what runs on :3478STUN and TURN commonly listen on UDP 3478 and may also accept TCP there; the IANA service description is specifically “STUN Behavior Discovery over TCP.” STUN messages have a 20-byte header with a magic cookie and transaction ID, and use message types and attributes for requests and responses. RFC 5780 behavior discovery uses attributes such as OTHER-ADDRESS and RESPONSE-ORIGIN to test NAT mapping and filtering behavior, and requires a suitably configured server with alternate addresses or ports. TURN uses STUN framing for allocation, permission, and channel operations, then relays client traffic. TLS is available but is not the default on 3478; deployments commonly use 5349 for STUN/TURN over TLS.
Security Information
exposure of :3478risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
network services averages 2.7 across 1,400 ports — this one sits 1.3 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
A public STUN listener is normal when providing connectivity services, but it can reveal mapped public addresses and should be monitored and rate-limited. TURN should require authentication and relay restrictions: an unauthenticated or misconfigured open relay can be abused to carry unwanted traffic and consume bandwidth. Traffic on 3478 is not encrypted by default, so use TLS where transport confidentiality is needed.
Related Ports
the 8 most looked-up other ports in network services — 1,400 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :6543 | Jetnet | UDP | Network Services | caution | 65.3k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3233 | WhiskerControl Protocol | TCPUDP | Network Services | caution | 61.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Tatsoft Default HTTP Proxy | TCP | Web Services | caution | 46.8k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted