Port 5349STUN/TURN over TLS

STUN behavior discovery and secure STUN/TURN clients use TLS on TCP port 5349.

transport
tcp

single transport

in transit
encrypted

payload protected on the wire

assignment
official

registered with iana

risk
4/10

caution

lookups
0

rank 993 of 5,442 · top 18%

also known as stun-behaviors, STUN over TLS, STUNS, TURNS, TURN over TLS/DTLS, TURN/TLS, TURN over DTLS, STUN over TLS/DTLS, STUN over DTLS

Technical Details

what runs on :5349

A client first establishes a TLS connection, then exchanges STUN messages over the connection using STUN's binary message format. TCP port 5349 is the conventional port for STUN over TLS and TURN over TLS; the corresponding non-TLS service commonly uses port 3478. The assigned behavior-discovery purpose relates to STUN extensions for probing NAT mapping and filtering behavior, which require a suitably configured server; not every STUN/TURN listener supports those probes.

Security Information

exposure of :5349

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 2.6 across 1,637 ports — this one sits 1.4 above.

in transit

encrypted

payloads are protected on the wire

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

TLS encrypts the connection, but an exposed listener can still reveal STUN-derived network information or provide a TURN relay. Public service is normal, but TURN should require authentication and be configured to prevent unauthorized relay use and bandwidth abuse; keep TLS and server software maintained.

the 8 most looked-up other ports in network services — 1,637 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted