Port 647DHCP Failover

Port 647 is officially designated for the DHCP Failover protocol, which enables communication between primary and secondary DHCP servers to maintain IP address allocation consistency and high availability. By synchronizing lease information, this protocol plays a crucial role in ensuring continuous network connectivity and minimizing IP conflicts during server outages..

transport
tcp

single transport

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
11,115

rank 382 of 993 · top 38%

Technical Details

what runs on :647
  • Overview: The DHCP Failover Protocol, operating on port 647, allows two DHCP servers to work in tandem, maintaining consistent lease databases and providing fault tolerance within enterprise networks. The protocol facilitates real-time communication between active and standby servers to ensure seamless IP address management.

  • Mechanism: This protocol uses a TCP-based connection to guarantee reliable state synchronization between partnering servers. During normal operation, lease allocations, renewals, and expirations are continuously exchanged, ensuring both servers have up-to-date information. If one server fails, the partner can continue issuing leases without client disruption.

  • Deployment Considerations: DHCP failover configurations support various modes like 'load balance' and 'hot standby' for different redundancy needs. Proper configuration ensures minimal recovery times and consistent client experiences during network issues or planned maintenance windows.

Security Information

exposure of :647

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

  • Common Vulnerabilities:

    • Lack of authentication on the failover communication channel can expose the system to man-in-the-middle attacks.
    • Unencrypted communication may lead to disclosure of sensitive network details.
    • Improper segmentation may allow attackers lateral movement targeting DHCP infrastructure.
  • Common Mitigations:

    • Implement network segmentation and firewalls to restrict access to port 647 only between authorized DHCP servers.
    • Use VPNs or secure tunnels between failover partners to protect data in transit.
    • Monitor DHCP server logs and failover state changes for anomalies.
    • Regularly update DHCP server software to patch known vulnerabilities.

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted