Port 11211: Memcached distributed memory cache
IANA registers 11211 over TCP and UDP as memcache (memory cache service). Since version 1.5.6, Memcached disables its UDP listener by default and listens only on TCP 11211.
Port Details
Security Exposure
CISA's UDP-based amplification alert lists Memcached with a bandwidth amplification factor of 10,000 to 51,000, and cites a February 2018 report of Memcached-based reflection DDoS via port 11211. The Memcached project disabled UDP by default in 1.5.6 after those attacks. Its configuration guide states that Memcached does not spend much effort defending against random internet connections and must not be exposed to the internet or other untrusted users.
Hardening
- +Bind Memcached to loopback or a private interface with the -l option.
- +Run Memcached 1.5.6 or later, where UDP is disabled by default, and do not re-enable it.
- +Firewall 11211 so only application servers can connect.
- +Use SASL authentication where supported, while still relying on network isolation, since the Memcached guide says SASL helps but should not be totally trusted.
Monitoring
Watch for inbound 11211 traffic from outside the application tier and for large outbound UDP responses from cache hosts, which indicate reflection abuse.
Tools for Auditing and Monitoring Memcached
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Suricata
Open SourceHigh-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.
Related Tool Categories
Frequently Asked Questions
Is port 11211 TCP or UDP?→
IANA registers both. Memcached 1.5.6 and later disable UDP by default, so current installs normally use TCP only.
Why is exposed Memcached dangerous?→
Memcached has little protection against untrusted connections, and its UDP mode was abused for DDoS reflection with amplification factors CISA lists as 10,000 to 51,000.
Should port 11211 be open to the internet?→
No. The Memcached project says it must not be exposed to the internet or other untrusted users.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 11211 is not guaranteed to be Memcached. Exploited-in-the-wild data from the CISA KEV catalog (CC0).