Port 647DHCP Failover
Port 647 is officially designated for the DHCP Failover protocol, which enables communication between primary and secondary DHCP servers to maintain IP address allocation consistency and high availability. By synchronizing lease information, this protocol plays a crucial role in ensuring continuous network connectivity and minimizing IP conflicts during server outages..
- transport
- tcp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 11,115
single transport
payload readable on path
registered with iana
caution
rank 382 of 993 · top 38%
Technical Details
what runs on :647-
Overview: The DHCP Failover Protocol, operating on port 647, allows two DHCP servers to work in tandem, maintaining consistent lease databases and providing fault tolerance within enterprise networks. The protocol facilitates real-time communication between active and standby servers to ensure seamless IP address management.
-
Mechanism: This protocol uses a TCP-based connection to guarantee reliable state synchronization between partnering servers. During normal operation, lease allocations, renewals, and expirations are continuously exchanged, ensuring both servers have up-to-date information. If one server fails, the partner can continue issuing leases without client disruption.
-
Deployment Considerations: DHCP failover configurations support various modes like 'load balance' and 'hot standby' for different redundancy needs. Proper configuration ensures minimal recovery times and consistent client experiences during network issues or planned maintenance windows.
Security Information
exposure of :647risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
network services averages 3.9 across 604 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp
every listening transport is another surface to filter at the edge
security overview
-
Common Vulnerabilities:
- Lack of authentication on the failover communication channel can expose the system to man-in-the-middle attacks.
- Unencrypted communication may lead to disclosure of sensitive network details.
- Improper segmentation may allow attackers lateral movement targeting DHCP infrastructure.
-
Common Mitigations:
- Implement network segmentation and firewalls to restrict access to port 647 only between authorized DHCP servers.
- Use VPNs or secure tunnels between failover partners to protect data in transit.
- Monitor DHCP server logs and failover state changes for anomalies.
- Regularly update DHCP server software to patch known vulnerabilities.
Related Ports
the 8 most looked-up other ports in network services — 604 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :6543 | Jetnet | UDP | Network Services | caution | 65.3k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3233 | WhiskerControl Protocol | TCPUDP | Network Services | caution | 61.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Tatsoft Default HTTP Proxy | TCP | Web Services | caution | 46.8k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted