Skip to main content

Port Details

Port
123
Transport
UDP
Service
NTP
IANA service name
ntp
Range
System port (0-1023)

Security Exposure

ntpd versions before 4.2.7 answer the monlist command with a list of the last 600 IP addresses that connected to the server, which attackers abuse with spoofed requests to amplify traffic toward a victim (CVE-2013-5211, CISA alert TA14-013A). CISA lists NTP's bandwidth amplification factor as 556.9. RFC 8633 warns that NTP control (Mode 6) queries are also a vector for amplification attacks when left open.

Hardening

  • +Upgrade ntpd to version 4.2.7 or later, or disable monlist with the noquery restriction, as CISA advises.
  • +Use restrict default with nomodify, notrap, nopeer, and noquery, as shown in RFC 8633.
  • +Block NTP control message queries from outside the organization on public-facing servers (RFC 8633).
  • +Apply BCP 38 source address validation to reduce spoofed traffic.

Monitoring

Watch for NTP responses much larger than their requests, high response volumes to a single address, and Mode 6 or Mode 7 queries from outside the network.

Tools for Auditing and Monitoring NTP

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Suricata

Open Source
Network Monitoring Tools

High-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.

LicenseGPL-2.0-only
PlatformLinux, FreeBSD, macOS, Windows

Frequently Asked Questions

Is NTP TCP or UDP?→

NTP uses UDP port 123. IANA also registers TCP 123, but RFC 5905 defines NTP packets as UDP datagrams.

What is an NTP amplification attack?→

Attackers send small spoofed queries such as monlist to open NTP servers, which send much larger responses to the victim (CISA TA14-013A).

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 123 is not guaranteed to be NTP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).