Port 860iSCSI

iSCSI, defined in RFC 3720, stands for Internet Small Computer Systems Interface. It is a network protocol that enables the transport of block-level storage data over TCP/IP networks, allowing clients (initiators) to transmit SCSI commands to storage devices (targets) located remotely. This capability facilitates Storage Area Network (SAN) implementations without dedicated fiber channel infrastructure..

transport
tcp

single transport

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
7,349

rank 697 of 993 · top 70%

Technical Details

what runs on :860

iSCSI (Internet Small Computer Systems Interface) is a transport layer protocol standardized in RFC 3720, designed to carry SCSI commands over IP networks. It encapsulates SCSI command sequences within TCP packets, enabling servers and storage to communicate over existing IP infrastructures instead of specialized storage networks like Fibre Channel. This reduces the cost and complexity of storage networking, enabling broad adoption in enterprise data centers.

Key elements in an iSCSI architecture include the initiators (clients, often servers or virtual servers) and targets (storage devices like SAN disks or arrays). iSCSI supports multiple session and connection constructs, allowing for robust, multipath configurations that ensure redundancy and load balancing. Security and authentication mechanisms are built into the protocol stack, such as CHAP (Challenge Handshake Authentication Protocol).

Usage of port 860 is primarily for iSCSI control and discovery sessions, with data transmission often occurring on negotiated higher ephemeral ports or other dedicated ports depending on configuration. This standardization enables flexible deployment of SANs across geographically distributed networks.

Security Information

exposure of :860

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

databases averages 4.0 across 58 ports — this one sits level with it.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

Common Vulnerabilities:

  • Unencrypted iSCSI traffic susceptible to eavesdropping and man-in-the-middle attacks
  • Weak authentication configurations (e.g., no CHAP or weak CHAP secrets)
  • Exposure of port 860 to untrusted networks increasing attack surface
  • Susceptibility to DoS attacks by flooding control or data sessions

Common Mitigations:

  • Employ IPsec or VLAN segmentation to encrypt or isolate iSCSI traffic
  • Always enable strong CHAP authentication or mutual CHAP
  • Restrict port 860 access using firewalls to trusted IP ranges
  • Monitor for anomalous login attempts and traffic patterns
  • Keep iSCSI target software and firmware up to date with security patches
  • Use network segmentation and dedicated storage VLANs to limit exposure

the 8 most looked-up other ports in databases — 58 ports carry that label.

risk mix of the 8 listed

  • caution100%

1 of 8 encrypted