Port 3653Tunnel Setup Protocol

Port 3653 is assigned to the Tunnel Setup Protocol for establishing network tunnels.

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
0

rank 993 of 4,248 · top 23%

also known as tsp

Technical Details

what runs on :3653

Tunnel Setup Protocol (TSP) uses XML request/response exchanges to negotiate tunnel creation, client authentication, IPv6 addresses or prefixes, and tunnel parameters. It is registered for both TCP and UDP on port 3653; TCP is commonly used for the control exchange, while UDP is supported by some implementations. The resulting IPv6 tunnel traffic is separate from the setup connection and may use IPv6-in-IPv4 protocol 41 or another negotiated tunnel mode.

Security Information

exposure of :3653

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 2.7 across 1,329 ports — this one sits 1.3 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

TSP setup traffic is not encrypted by default, so credentials and tunnel parameters may be exposed unless the deployment adds transport protection. An exposed server can be probed for authentication weaknesses or abused to consume tunnel resources and provide unintended IPv6 transit; restrict provisioning to intended clients and use authenticated, protected deployments.

the 8 most looked-up other ports in network services — 1,329 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted