Port 4784BFD Multihop Control
BFD Multihop Control detects forwarding-path failures between nonadjacent network devices.
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 0
2 transports registered
payload readable on path
registered with iana
caution
rank 994 of 2,577 · top 39%
also known as bfd-multi-ctl, Bidirectional Forwarding Detection multihop
Technical Details
what runs on :4784BFD provides rapid, lightweight failure detection by exchanging periodic control packets between session endpoints and tracking negotiated transmit and receive intervals, session state, and a detection multiplier. Multihop BFD uses UDP destination port 4784 and supports paths spanning one or more routed hops; it is not normally a TCP protocol, despite the TCP assignment also present in the registry. Related BFD assignments include UDP 3784 for single-hop control and UDP 3785 for BFD Echo. BFD packets are not encrypted by default, and authentication is optional.
Security Information
exposure of :4784risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
security averages 3.4 across 281 ports — this one sits 0.6 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
BFD is a network-control protocol rather than an application service and should normally be restricted to explicitly configured peers with network ACLs. An attacker able to inject or disrupt BFD packets may flap sessions, trigger routing or forwarding failover, or consume device resources; the cleartext protocol also provides no confidentiality by default. It should not be exposed broadly to the public internet.
Related Ports
the 8 most looked-up other ports in security — 281 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :443 | HTTPS | TCPtls | Web Services | caution | 65.9k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Squid Proxy HTTP | TCP | Web Services | caution | 45.8k |
| :8080 | HTTP Alternate | TCPtls | Web Services | caution | 44.9k |
| :7000 | Vuze HTTPS Tracker | TCPtls | Security | caution | 28.9k |
risk mix of the 8 listed
- caution100%
3 of 8 encrypted