Port 5678Mikrotik MNDP

The MikroTik Neighbor Discovery Protocol (MNDP) enables MikroTik RouterOS devices to detect and share information with nearby MikroTik routers on the same network segment. It facilitates device management by providing insights about device identities, IP details, and network topology, making administration straightforward for network operators..

transport
udp

single transport

in transit
cleartext

payload readable on path

assignment
unofficial

used by convention

risk
4/10

caution

lookups
24,656

rank 73 of 993 · top 7%

Technical Details

what runs on :5678

MikroTik Neighbor Discovery Protocol (MNDP) is a Layer 2 protocol specifically designed for MikroTik RouterOS devices, functioning similarly to protocols like Cisco Discovery Protocol (CDP) or Link Layer Discovery Protocol (LLDP). It allows MikroTik devices on the same broadcast domain to identify one another, simplifying large-scale RouterOS deployments.

MNDP operates over UDP port 5678, primarily using broadcast packets to announce the presence and details of a MikroTik device, such as device identity, MAC address, software version, interface IPs, and platform type. This information aids administrators in mapping network topologies and managing devices without manual configuration or IP scanning.

The protocol is lightweight and automatically enabled on RouterOS devices. It’s commonly integrated into device management workflows and incorporated within MikroTik’s WinBox GUI and command-line tools, enhancing operational awareness and troubleshooting capabilities.

Security Information

exposure of :5678

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

unofficial

used by convention, not registered — what answers here varies by deployment

reachable over

udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common vulnerabilities associated with MNDP include:

  • Exposure of sensitive device details (like identities and MAC addresses) to any listener on the same network segment.
  • Potential for enumeration by unauthorized users to gather information useful for targeted attacks or lateral movement.
  • Risk of spoofed MNDP packets that could mislead administrators or disrupt network mapping.

Mitigation strategies commonly include:

  • Disabling MNDP on interfaces connected to untrusted networks or the internet.
  • Restricting access to management interfaces with strong firewall rules and VLAN segmentation.
  • Using device authentication and securing other management protocols such as SSH or WinBox.
  • Monitoring network traffic for suspicious MNDP activity and practicing least privilege principles on administrative accounts.

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted