Port 4790VXLAN-GPE

UDP encapsulation for VXLAN overlays that can carry Ethernet, IP, or other payloads identified by a next-protocol field.

transport
udp

single transport

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
5/10

caution

lookups
0

rank 993 of 5,290 · top 19%

also known as VXLAN Generic Protocol Extension, UDP/4790

Technical Details

what runs on :4790

VXLAN-GPE uses UDP destination port 4790 and an 8-byte encapsulation header containing a 24-bit VNI and a next-protocol field to identify the encapsulated payload, such as Ethernet, IPv4, IPv6, or Network Service Header (NSH). It is a datagram tunnel protocol with no connection handshake; the UDP source port is commonly chosen to provide entropy for underlay load balancing. Ordinary VXLAN generally uses UDP port 4789 and does not use the GPE next-protocol extension.

Security Information

exposure of :4790

risk score

5/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 2.6 across 1,589 ports — this one sits 2.4 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

VXLAN-GPE does not provide encryption or peer authentication by default. A reachable endpoint may accept spoofed tunnel packets, potentially exposing or injecting traffic into an overlay, so restrict UDP/4790 to trusted tunnel endpoints and apply filtering and security controls to inner traffic. It is not generally appropriate to expose this port to the public internet.

the 8 most looked-up other ports in network services — 1,589 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted