Port 6080Generic UDP Encapsulation (GUE)

GUE carries network packets inside UDP datagrams for tunneling between network endpoints.

transport
udp

single transport

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
2/10

safe

lookups
0

rank 993 of 5,618 · top 18%

also known as gue

Technical Details

what runs on :6080

IANA assigns UDP 6080 to GUE, specified in RFC 8086. It is connectionless: there is no handshake, and each UDP datagram contains a GUE header identifying the encapsulated protocol, with optional extensions or control information, followed by the packet payload. GUE supports carrying network-layer packets through UDP, which can work across routed networks and with ECMP. The port is a convention for GUE tunnel traffic, not a guarantee that every listener on UDP 6080 speaks GUE.

Security Information

exposure of :6080

risk score

2/ 10safe

routine exposure. this port is rarely the way in on its own — keep it patched and logged and move on.

network services averages 2.6 across 1,684 ports — this one sits 0.6 below.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

GUE does not provide encryption or peer authentication itself. An exposed tunnel endpoint may accept spoofed or unauthorized encapsulated packets, potentially allowing traffic injection or abuse of the network behind it. Restrict access to trusted tunnel peers and apply source validation and filtering; a GUE endpoint generally should not be exposed broadly to the internet.

the 8 most looked-up other ports in network services — 1,684 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted