Port 5161SNMP over SSH

TCP 5161 carries SNMP management messages through an encrypted SSH connection.

transport
tcp

single transport

in transit
encrypted

payload protected on the wire

assignment
official

registered with iana

risk
4/10

caution

lookups
0

rank 993 of 5,397 · top 18%

also known as snmpssh, SNMP over SSH Transport Model, RFC 5592

Technical Details

what runs on :5161

The manager connects over TCP to port 5161 and establishes an SSH connection, then carries SNMP messages over an SSH channel using the SNMP subsystem. Messages use BER encoding with a four-octet length prefix for framing. SSH provides the negotiated encryption and integrity protection, while SSH user authentication and the SNMP security model provide identity and access control. This is distinct from ordinary SSH shell access on TCP 22 and from the commonly deployed SNMP-over-UDP service on port 161.

Security Information

exposure of :5161

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

security averages 3.1 across 385 ports — this one sits 0.9 above.

in transit

encrypted

payloads are protected on the wire

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

Traffic is encrypted and integrity-protected by SSH, but an exposed listener is still a remote SNMP management interface. Restrict it to trusted management networks, use strong SSH authentication, and limit SNMP permissions; attackers may probe for weak credentials or flaws in the SSH and SNMP implementations. It is uncommon in internet-wide scans, but should not be treated as harmless if present.

the 8 most looked-up other ports in security — 385 ports carry that label.

risk mix of the 8 listed

  • caution100%

2 of 8 encrypted