Port 546DHCPv6 Client

DHCPv6 Client is the Dynamic Host Configuration Protocol designed specifically for IPv6 networks. It automates the process of assigning IPv6 addresses and other configuration details to client devices, enabling seamless integration into IPv6-enabled networks. Unlike its IPv4 counterpart, DHCPv6 implements certain protocol-level improvements, including prefix delegation and improved multicast communication, to accommodate the unique requirements of IPv6..

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
16,647

rank 175 of 993 · top 18%

Technical Details

what runs on :546
  • Overview

DHCPv6 (Dynamic Host Configuration Protocol for IPv6) is the successor of DHCP for IPv4, built to manage network configuration in IPv6 environments. It enables automatic assignment of IPv6 addresses, prefixes, and configuration parameters (such as DNS servers) to clients on an IPv6 network.

  • How it works

Clients initiate communication using port 546 (client-side), sending DHCP solicit messages to locate available DHCPv6 servers (listening on port 547). DHCPv6 primarily uses multicast communication to improve efficiency, as IPv6 does not support broadcast messaging like IPv4. A significant feature is Prefix Delegation, where DHCPv6 servers can assign an entire prefix (a subnet block) to a requesting router, allowing downstream distribution.

  • Differences from DHCPv4

DHCPv6 avoids broadcast by relying on multicast, reducing unnecessary network noise. It introduces stateless and stateful address assignment options, better supports mobility, and includes prefix delegation. Unlike DHCPv4, it can coexist with IPv6 stateless address auto-configuration (SLAAC), complementing IPv6’s inbuilt address management capabilities.

Security Information

exposure of :546

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

  • Common Vulnerabilities

    • Rogue DHCPv6 servers: Attackers can set up unauthorized servers that assign malicious or incorrect network configurations, leading to Man-in-the-Middle attacks or denial-of-service.
    • DHCP starvation: Attackers repeatedly request addresses, exhausting the DHCP pool.
    • Relay agent exploitation: Compromise of DHCP relays can redirect or intercept traffic.
  • Common Mitigations

    • DHCPv6 snooping: On switches, use snooping features that filter unauthorized DHCP servers.
    • Access controls: Restrict the deployment of DHCP services and limit which devices can connect to trusted switch ports.
    • Use of IPsec: Employ IPsec to authenticate and encrypt DHCP exchanges where supported.
    • Monitoring and logging: Continuously monitor DHCP activity to detect anomalies such as sudden request spikes.
    • Prefix filtering: Limit prefix delegations to prevent unauthorized network expansion.

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted