Port 694Linux-HA Heartbeat

Port 694 is assigned to the Linux-HA project's Heartbeat component, a messaging layer that facilitates high-availability clustering in Linux environments. Heartbeat monitors and manages communication between cluster nodes, maintaining failover operations and resource management to ensure system uptime..

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
6,704

rank 763 of 993 · top 77%

Technical Details

what runs on :694

Linux-HA Heartbeat is a core process within the Linux-HA project designed to provide reliable messaging and node state monitoring within a clustered environment. It transmits periodic heartbeat signals over the network on port 694, enabling nodes to detect failures through missed messages. Heartbeat manages cluster membership using these signals, supporting both unicast and multicast communication via TCP and UDP.

Heartbeat coordinates failover activities, automatically reassigning resources such as IP addresses and file systems when a node becomes unresponsive. This orchestration ensures service continuity with minimal downtime, which is crucial for mission-critical systems. Heartbeat is often integrated with other cluster resource managers like Pacemaker for more advanced resource control and monitoring.

Port 694 usage is typically found in enterprise Linux deployment scenarios where high availability is necessary—such as web servers, databases, and network services. Since both TCP and UDP protocols are used, configuring proper firewall and network rules is essential to maintain reliable cluster communication without interruptions.

Security Information

exposure of :694

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common Vulnerabilities:

  • Exposure to unauthorized network segments may allow an attacker to inject spoofed heartbeat packets, potentially misleading cluster nodes or causing denial-of-service.
  • Lack of authentication or encryption by default leaves cluster management data vulnerable to interception and manipulation.
  • Exploitation could lead to illegitimate resource takeovers, data corruption, or cluster instability.

Common Mitigations:

  • Isolate heartbeat traffic on dedicated, trusted VLANs or separate physical interfaces to limit exposure.
  • Employ IPsec or VPN tunneling to encrypt cluster communications, preventing tampering and snooping.
  • Implement access control lists (ACLs) to restrict port 694 traffic to known cluster nodes.
  • Regularly update and harden cluster software components to address discovered vulnerabilities and reduce attack surface.

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted