Port 3799RADIUS Dynamic Authorization

RADIUS Dynamic Authorization for changing or terminating active network access sessions.

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
6/10

risk

lookups
0

rank 994 of 2,485 · top 40%

also known as radius-dynauth, RADIUS CoA, RADIUS Disconnect

Technical Details

what runs on :3799

RADIUS Dynamic Authorization is defined by RFC 5176 and normally uses UDP port 3799; the registry also assigns the service over TCP. Messages use the RADIUS packet format with a code, identifier, length, authenticator, and typed attributes, followed by a request/response exchange rather than a connection-oriented handshake. Requests are authenticated with a shared secret and commonly a Message-Authenticator attribute. Standard RADIUS authentication and accounting commonly use UDP ports 1812 and 1813.

Security Information

exposure of :3799

risk score

6/ 10risk

treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.

security averages 3.5 across 272 ports — this one sits 2.5 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Dynamic Authorization can change authorization state or disconnect active users, so an exposed endpoint is a sensitive control interface. It is not encrypted by default and should be restricted to trusted RADIUS peers with filtering, strong shared secrets, and message authentication; it should generally not be reachable from the public internet.

the 8 most looked-up other ports in security — 272 ports carry that label.

risk mix of the 8 listed

  • caution100%

3 of 8 encrypted