Port 4336RESTCONF Call Home over TLS

TLS-protected RESTCONF Call Home listener for controllers; managed devices initiate connections back to it.

transport
tcp

single transport

in transit
encrypted

payload protected on the wire

assignment
official

registered with iana

risk
3/10

caution

lookups
0

rank 993 of 5,134 · top 19%

also known as restconf-ch-tls

Technical Details

what runs on :4336

TCP 4336 is the controller-side listener for RESTCONF Call Home over TLS (RFC 8071). The managed RESTCONF server initiates the TCP connection and acts as the TLS client; after the TLS handshake, RESTCONF uses HTTP semantics as specified in RFC 8040, with the managed device still serving the RESTCONF API. This is distinct from the more usual arrangement where a client connects to a device's HTTPS RESTCONF endpoint, commonly on port 443. The port has no separate application framing beyond HTTP over TLS.

Security Information

exposure of :4336

risk score

3/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

web services averages 3.1 across 191 ports — this one sits 0.1 below.

in transit

encrypted

payloads are protected on the wire

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

TLS protects the connection, and deployments should authenticate the connecting device and validate credentials and certificates appropriately. This listener provides access to a network-management API, so restrict it to expected devices or management networks and keep RESTCONF authorization and TLS configuration current; do not expose it broadly just because it uses TLS.

the 8 most looked-up other ports in web services — 191 ports carry that label.

risk mix of the 8 listed

  • safe13%
  • caution88%

0 of 8 encrypted