Port 5678Mikrotik MNDP
The MikroTik Neighbor Discovery Protocol (MNDP) enables MikroTik RouterOS devices to detect and share information with nearby MikroTik routers on the same network segment. It facilitates device management by providing insights about device identities, IP details, and network topology, making administration straightforward for network operators..
- transport
- udp
- in transit
- cleartext
- assignment
- unofficial
- risk
- 4/10
- lookups
- 24,656
single transport
payload readable on path
used by convention
caution
rank 73 of 993 · top 7%
Technical Details
what runs on :5678MikroTik Neighbor Discovery Protocol (MNDP) is a Layer 2 protocol specifically designed for MikroTik RouterOS devices, functioning similarly to protocols like Cisco Discovery Protocol (CDP) or Link Layer Discovery Protocol (LLDP). It allows MikroTik devices on the same broadcast domain to identify one another, simplifying large-scale RouterOS deployments.
MNDP operates over UDP port 5678, primarily using broadcast packets to announce the presence and details of a MikroTik device, such as device identity, MAC address, software version, interface IPs, and platform type. This information aids administrators in mapping network topologies and managing devices without manual configuration or IP scanning.
The protocol is lightweight and automatically enabled on RouterOS devices. It’s commonly integrated into device management workflows and incorporated within MikroTik’s WinBox GUI and command-line tools, enhancing operational awareness and troubleshooting capabilities.
Security Information
exposure of :5678risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
network services averages 3.9 across 604 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
unofficial
used by convention, not registered — what answers here varies by deployment
reachable over
udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
Common vulnerabilities associated with MNDP include:
- Exposure of sensitive device details (like identities and MAC addresses) to any listener on the same network segment.
- Potential for enumeration by unauthorized users to gather information useful for targeted attacks or lateral movement.
- Risk of spoofed MNDP packets that could mislead administrators or disrupt network mapping.
Mitigation strategies commonly include:
- Disabling MNDP on interfaces connected to untrusted networks or the internet.
- Restricting access to management interfaces with strong firewall rules and VLAN segmentation.
- Using device authentication and securing other management protocols such as SSH or WinBox.
- Monitoring network traffic for suspicious MNDP activity and practicing least privilege principles on administrative accounts.
Related Ports
the 8 most looked-up other ports in network services — 604 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :6543 | Jetnet | UDP | Network Services | caution | 65.3k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3233 | WhiskerControl Protocol | TCPUDP | Network Services | caution | 61.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Tatsoft Default HTTP Proxy | TCP | Web Services | caution | 46.8k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted