Port 3478STUN / TURN

STUN and TURN commonly use port 3478 for NAT discovery and relaying; the IANA handle specifically denotes STUN behavior discovery over TCP.

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
0

rank 993 of 4,715 · top 21%

also known as stun-behavior, RFC 5780

2 other services are registered on port 3478. compare all 3 →

Technical Details

what runs on :3478

STUN and TURN commonly listen on UDP 3478 and may also accept TCP there; the IANA service description is specifically “STUN Behavior Discovery over TCP.” STUN messages have a 20-byte header with a magic cookie and transaction ID, and use message types and attributes for requests and responses. RFC 5780 behavior discovery uses attributes such as OTHER-ADDRESS and RESPONSE-ORIGIN to test NAT mapping and filtering behavior, and requires a suitably configured server with alternate addresses or ports. TURN uses STUN framing for allocation, permission, and channel operations, then relays client traffic. TLS is available but is not the default on 3478; deployments commonly use 5349 for STUN/TURN over TLS.

Security Information

exposure of :3478

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 2.7 across 1,400 ports — this one sits 1.3 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

A public STUN listener is normal when providing connectivity services, but it can reveal mapped public addresses and should be monitored and rate-limited. TURN should require authentication and relay restrictions: an unauthenticated or misconfigured open relay can be abused to carry unwanted traffic and consume bandwidth. Traffic on 3478 is not encrypted by default, so use TLS where transport confidentiality is needed.

the 8 most looked-up other ports in network services — 1,400 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted