Skip to main content

Port Details

Port
11211
Transport
TCP / UDP
Service
Memcached
IANA service name
memcache
Range
User port (1024-49151)

Security Exposure

CISA's UDP-based amplification alert lists Memcached with a bandwidth amplification factor of 10,000 to 51,000, and cites a February 2018 report of Memcached-based reflection DDoS via port 11211. The Memcached project disabled UDP by default in 1.5.6 after those attacks. Its configuration guide states that Memcached does not spend much effort defending against random internet connections and must not be exposed to the internet or other untrusted users.

Hardening

  • +Bind Memcached to loopback or a private interface with the -l option.
  • +Run Memcached 1.5.6 or later, where UDP is disabled by default, and do not re-enable it.
  • +Firewall 11211 so only application servers can connect.
  • +Use SASL authentication where supported, while still relying on network isolation, since the Memcached guide says SASL helps but should not be totally trusted.

Monitoring

Watch for inbound 11211 traffic from outside the application tier and for large outbound UDP responses from cache hosts, which indicate reflection abuse.

Tools for Auditing and Monitoring Memcached

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Suricata

Open Source
Network Monitoring Tools

High-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.

LicenseGPL-2.0-only
PlatformLinux, FreeBSD, macOS, Windows

Frequently Asked Questions

Is port 11211 TCP or UDP?→

IANA registers both. Memcached 1.5.6 and later disable UDP by default, so current installs normally use TCP only.

Why is exposed Memcached dangerous?→

Memcached has little protection against untrusted connections, and its UDP mode was abused for DDoS reflection with amplification factors CISA lists as 10,000 to 51,000.

Should port 11211 be open to the internet?→

No. The Memcached project says it must not be exposed to the internet or other untrusted users.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 11211 is not guaranteed to be Memcached. Exploited-in-the-wild data from the CISA KEV catalog (CC0).