Port 1194: OpenVPN tunnel
Port 1194 is the IANA-assigned port for OpenVPN and its default since version 2.0-beta17; earlier versions used port 5000. OpenVPN uses UDP by default and can also run over TCP (tcp-client and tcp-server).
Port Details
Security Exposure
A VPN listener has to face the internet, which makes it an entry point that CISA and NSA say malicious actors target for credential harvesting and remote code execution. OpenVPN documents that without tls-auth, unauthorized hosts can start TLS handshakes, scan for the listening UDP port and flood it.
Hardening
- +Enable tls-crypt or tls-auth so packets without the correct HMAC are dropped before TLS processing.
- +Use certificate-based client authentication and add multi-factor authentication for remote users, as the NSA and CISA VPN guidance advises.
- +Run the daemon with reduced privileges (user nobody, group nobody) after initialization.
- +Keep OpenVPN and its TLS library patched.
- +Revoke certificates of departed users and devices and check them with crl-verify.
Monitoring
Log connection attempts, TLS handshake failures and authentication results, and alert on high failure rates or logins from unexpected locations.
Tools for Auditing and Monitoring OpenVPN
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Suricata
Open SourceHigh-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.
Related Tool Categories
Frequently Asked Questions
Is OpenVPN port 1194 TCP or UDP?→
OpenVPN supports both. The manual lists udp, tcp-client and tcp-server for the proto option, and 1194 is the default port.
What does tls-auth protect against?→
OpenVPN documents that tls-auth adds an HMAC to handshake packets, which helps against DoS or port flooding on the UDP port, port scanning and unauthorized TLS handshakes.
Sources
- IANA Service Name and Port Number Registry: port 1194
- OpenVPN 2.6 reference manual
- OpenVPN: Hardening OpenVPN Security
- CISA: CISA and NSA Release Guidance on Selecting and Hardening VPNs
- NSA and CISA: Selecting and Hardening Remote Access VPN Solutions (PDF)
- NSA: NSA, CISA Release Guidance on Selecting and Hardening Remote Access VPNs
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 1194 is not guaranteed to be OpenVPN. Exploited-in-the-wild data from the CISA KEV catalog (CC0).