Skip to main content

Port Details

Port
1194
Transport
UDP / TCP
Service
OpenVPN
IANA service name
openvpn
Range
User port (1024-49151)

Security Exposure

A VPN listener has to face the internet, which makes it an entry point that CISA and NSA say malicious actors target for credential harvesting and remote code execution. OpenVPN documents that without tls-auth, unauthorized hosts can start TLS handshakes, scan for the listening UDP port and flood it.

Hardening

  • +Enable tls-crypt or tls-auth so packets without the correct HMAC are dropped before TLS processing.
  • +Use certificate-based client authentication and add multi-factor authentication for remote users, as the NSA and CISA VPN guidance advises.
  • +Run the daemon with reduced privileges (user nobody, group nobody) after initialization.
  • +Keep OpenVPN and its TLS library patched.
  • +Revoke certificates of departed users and devices and check them with crl-verify.

Monitoring

Log connection attempts, TLS handshake failures and authentication results, and alert on high failure rates or logins from unexpected locations.

Tools for Auditing and Monitoring OpenVPN

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Suricata

Open Source
Network Monitoring Tools

High-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.

LicenseGPL-2.0-only
PlatformLinux, FreeBSD, macOS, Windows

Frequently Asked Questions

Is OpenVPN port 1194 TCP or UDP?→

OpenVPN supports both. The manual lists udp, tcp-client and tcp-server for the proto option, and 1194 is the default port.

What does tls-auth protect against?→

OpenVPN documents that tls-auth adds an HMAC to handshake packets, which helps against DoS or port flooding on the UDP port, port scanning and unauthorized TLS handshakes.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 1194 is not guaranteed to be OpenVPN. Exploited-in-the-wild data from the CISA KEV catalog (CC0).