Port 910Kerberized Internet Negotiation of Keys (KINK)

KINK negotiates IPsec security associations using Kerberos authentication over TCP or UDP port 910.

transport
tcp · udp

2 transports registered

in transit
encrypted

payload protected on the wire

assignment
official

registered with iana

risk
2/10

safe

lookups
0

rank 994 of 2,045 · top 49%

also known as kink, Kerberized Internet Negotiation of Keys

Technical Details

what runs on :910

KINK is a binary key-management protocol that uses Kerberos for peer authentication and negotiates IPsec security associations. It exchanges structured request and response messages over TCP or UDP port 910, with Kerberos-protected authentication and keying material rather than the certificate- or pre-shared-key exchanges commonly associated with IKE. Kerberos itself normally uses port 88, while IKE uses UDP 500 and UDP 4500; those ports are related technologies, not alternate KINK ports.

Security Information

exposure of :910

risk score

2/ 10safe

routine exposure. this port is rarely the way in on its own — keep it patched and logged and move on.

security averages 3.6 across 254 ports — this one sits 1.6 below.

in transit

encrypted

payloads are protected on the wire

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

KINK should generally be restricted to hosts and networks that require Kerberos-based IPsec negotiation rather than exposed broadly to the Internet. Kerberos authentication limits unauthorized negotiation, but an exposed listener can still be probed or targeted for denial of service, and its security depends on correct realm configuration, service principals, and Kerberos cryptography.

the 8 most looked-up other ports in security — 254 ports carry that label.

risk mix of the 8 listed

  • caution100%

3 of 8 encrypted