Port 8472Overlay Transport Virtualization (OTV)

Cisco OTV carries Layer 2 Ethernet traffic across an IP transport between overlay edge devices.

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
6/10

risk

lookups
0

rank 994 of 3,368 · top 29%

also known as otv, Cisco OTV

Technical Details

what runs on :8472

OTV encapsulates Ethernet frames in an IP-based overlay between OTV edge devices; normal deployments use UDP port 8472 for the data plane, with OTV control-plane mechanisms maintaining reachability and site information. The outer transport is commonly multicast or unicast IP depending on the deployment, and the encapsulated traffic is not encrypted by OTV itself. UDP/8472 is distinct from VXLAN's UDP/4789.

Security Information

exposure of :8472

risk score

6/ 10risk

treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.

network services averages 2.8 across 1,173 ports — this one sits 3.2 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

OTV should be restricted to trusted data-center transport networks rather than exposed to the public Internet. Because native OTV does not provide confidentiality and can extend Layer 2 traffic across sites, an exposed or insufficiently filtered endpoint could enable unauthorized overlay participation or access to bridged networks; use network filtering and an appropriate encrypted underlay where required.

the 8 most looked-up other ports in network services — 1,173 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted