Port 427Service Location Protocol
The Service Location Protocol (SLP) enables devices to discover services available on a local network dynamically and without prior configuration. It simplifies network management by providing a scalable, flexible, and decentralized mechanism to advertise and locate services, such as printers or file servers, reducing the need for manual setup. SLP supports both TCP and UDP communications to ensure compatibility and resilience across diverse network environments and topologies..
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 14,631
2 transports registered
payload readable on path
registered with iana
caution
rank 230 of 993 · top 23%
Technical Details
what runs on :427Service Location Protocol (SLP), standardized by the IETF in RFC 2608, facilitates the discovery and advertisement of network services within a local area network (LAN). It operates using a decentralized architecture where User Agents (UAs) query for services, Service Agents (SAs) register services, and Directory Agents (DAs) can optionally centralize service information to improve scalability.
Typically, SLP uses multicast to locate Directory Agents dynamically, or when no DA is available, clients interact directly with Service Agents via multicast. Service descriptions are advertised using standardized templates that provide service-specific attributes, enabling clients to perform rich, attribute-based queries. This flexibility allows SLP to function efficiently in small home networks with zero configuration, as well as in large enterprise domains.
SLP supports both TCP and UDP transport over port 427, with UDP favored for lightweight queries and TCP for reliable or extended transactions. Its support for multiple transports enhances robustness but requires proper handling in network infrastructure such as firewalls. Though primarily designed for IPv4, SLP also has IPv6 support, making it relevant in modern dual-stack environments.
Security Information
exposure of :427risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
network services averages 3.9 across 604 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
Common vulnerabilities of SLP include susceptibility to unauthorized service registration or discovery, which can lead to enumeration attacks or service impersonation. Malicious actors might exploit SLP to inject rogue service advertisements, mislead clients, or conduct denial of service by overwhelming the protocol's multicast-based service lookup mechanism. Since SLP was designed in an era with less stringent security concerns, it lacks native authentication and encryption, increasing its attack surface if exposed beyond trusted networks.
Mitigation strategies involve restricting SLP communications to trusted subnets using access control lists and firewall policies, preventing untrusted hosts from registering or querying services. Deploying SLP within tightly controlled enterprise segments ensures only authenticated devices can interact with service directories. Where available, organizations should consider implementing network segmentation and monitoring to detect anomalous SLP activity. Additionally, transitioning to more secure, authenticated service discovery methods is recommended when feasible.
Related Ports
the 8 most looked-up other ports in network services — 604 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :6543 | Jetnet | UDP | Network Services | caution | 65.3k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3233 | WhiskerControl Protocol | TCPUDP | Network Services | caution | 61.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Tatsoft Default HTTP Proxy | TCP | Web Services | caution | 46.8k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted