Port 4335NETCONF Call Home over TLS

TCP 4335 is used by network devices to initiate TLS-protected NETCONF management sessions to a controller.

transport
tcp

single transport

in transit
encrypted

payload protected on the wire

assignment
official

registered with iana

risk
7/10

risk

lookups
0

rank 993 of 5,134 · top 19%

also known as netconf-ch-tls, NETCONF over TLS Call Home

Technical Details

what runs on :4335

The device initiates a TCP connection to the manager on port 4335, then establishes TLS before exchanging NETCONF protocol messages. NETCONF hello messages negotiate capabilities, after which the peers exchange framed RPC requests and replies. This port is for NETCONF Call Home over TLS (RFC 8071); port 6513 is the conventional port for NETCONF over TLS without the Call Home assignment.

Security Information

exposure of :4335

risk score

7/ 10risk

treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.

remote access averages 3.8 across 204 ports — this one sits 3.2 above.

in transit

encrypted

payloads are protected on the wire

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

TLS protects the management session, but the service provides access to sensitive device configuration and operational data. Restrict the listener to expected device networks, validate peer certificates and identities, and keep NETCONF authorization narrowly scoped; it is not a general-purpose public service.

the 8 most looked-up other ports in remote access — 204 ports carry that label.

risk mix of the 8 listed

  • safe13%
  • caution88%

0 of 8 encrypted