Port 4789VXLAN

VXLAN carries Layer 2 Ethernet frames across an IP network inside UDP, commonly for data-center and cloud network overlays.

transport
udp

single transport

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
6/10

risk

lookups
0

rank 993 of 5,290 · top 19%

also known as UDP 4789

Technical Details

what runs on :4789

VXLAN encapsulates an Ethernet frame in a VXLAN header and an outer UDP/IP packet; the standard destination port is UDP 4789 (older implementations may use UDP 8472). The header carries a 24-bit VXLAN Network Identifier (VNI), allowing many isolated overlay segments to share an underlay. Endpoints typically send to UDP destination port 4789, often using a varying UDP source port to support underlay load balancing. VXLAN does not provide encryption or peer authentication.

Security Information

exposure of :4789

risk score

6/ 10risk

treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.

network services averages 2.6 across 1,589 ports — this one sits 3.4 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

VXLAN is intended for a controlled network underlay, not unrestricted internet exposure. Because it has no built-in authentication or encryption, an exposed endpoint may accept or inject encapsulated traffic depending on its configuration, potentially enabling access to overlay networks; restrict the port to trusted peers and use IPsec or another protected underlay when needed.

the 8 most looked-up other ports in network services — 1,589 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted