Port 3784Bidirectional Forwarding Detection (BFD)
BFD control traffic rapidly detects forwarding-path failures between network devices.
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- official
- risk
- 5/10
- lookups
- 0
2 transports registered
payload readable on path
registered with iana
caution
rank 994 of 1,459 · top 68%
also known as bfd-control, BFD, Bidirectional Forwarding Detection
1 other service is registered on port 3784. compare all 2 →
Technical Details
what runs on :3784BFD uses a control-session state machine with Down, Init, and Up states. Peers exchange periodically timed control packets containing negotiated transmit and receive intervals, a detection multiplier, session identifiers, and discriminator values; a session is declared failed when the expected number of packets is missed. Standard BFD control uses UDP/3784, while BFD Echo uses UDP/3785 and multihop BFD commonly uses UDP/4784. The registry assignment also lists TCP/3784, although conventional BFD implementations use UDP.
Security Information
exposure of :3784risk score
5/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
security averages 3.8 across 227 ports — this one sits 1.2 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
BFD is not encrypted by default. An exposed endpoint can be targeted with forged or disruptive control traffic to force sessions down or consume device resources; authentication is available in BFD implementations but is not universally enabled. BFD should normally be restricted to configured peer addresses and protected with interface, ACL, control-plane policing, and anti-spoofing controls rather than exposed to the public internet.
Related Ports
the 8 most looked-up other ports in security — 227 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :443 | HTTPS | TCPtls | Web Services | caution | 65.9k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Squid Proxy HTTP | TCP | Web Services | caution | 45.8k |
| :8080 | HTTP Alternate | TCPtls | Web Services | caution | 44.9k |
| :7000 | Vuze HTTPS Tracker | TCPtls | Security | caution | 28.9k |
risk mix of the 8 listed
- caution100%
3 of 8 encrypted