Port 1701: Layer 2 Tunneling Protocol
L2TP tunnels PPP sessions between an access concentrator and a network server and runs over UDP port 1701 (RFC 2661). Remote access VPNs typically run it inside IPsec, a combination defined in RFC 3193 and known as L2TP/IPsec. Windows Routing and Remote Access lists L2TP on UDP 1701.
Port Details
Security Exposure
RFC 3193 relies on IPsec to give L2TP tunnel authentication, privacy protection, integrity checking and replay protection, so L2TP sent without IPsec lacks those properties. An internet-facing L2TP endpoint also adds VPN attack surface for credential guessing against the PPP layer. Microsoft has deprecated L2TP and PPTP in Windows Server, citing well-documented vulnerabilities, and new RRAS setups in Windows Server 2025 do not accept L2TP connections by default.
Hardening
- +Accept L2TP only when it is protected by IPsec and drop UDP 1701 packets that arrive outside an IPsec security association.
- +Plan migration to IKEv2 or SSTP, the tunnel types Microsoft recommends in place of L2TP.
- +Leave L2TP disabled on Windows Server 2025 RRAS unless a legacy client population still requires it.
- +Limit UDP 500, 4500 and 1701 at the firewall to the gateways that actually terminate L2TP/IPsec.
Monitoring
Watch for UDP 1701 traffic that is not carried inside ESP, and for tunnel setup attempts against hosts that are not designated VPN gateways. Track repeated PPP authentication failures on the VPN server.
Tools for Auditing and Monitoring L2TP
OPNsense
Free / CommercialOpen source FreeBSD firewall and routing platform with IDS integration and a paid business edition.
Wireshark
Open SourceNetwork packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Related Tool Categories
Frequently Asked Questions
Is L2TP port 1701 TCP or UDP?→
L2TP uses UDP. RFC 2661 assigns UDP port 1701 as the destination for L2TP tunnel traffic.
Does L2TP encrypt traffic on its own?→
RFC 3193 describes how L2TP uses IPsec to provide tunnel authentication, privacy protection, integrity checking and replay protection. Deployments therefore pair L2TP with IPsec instead of running it alone.
Is L2TP still supported on Windows Server?→
Microsoft has deprecated L2TP and PPTP. Beginning with Windows Server 2025, new RRAS setups do not accept L2TP or PPTP connections by default, though administrators can still enable them.
Sources
- IANA Service Name and Transport Protocol Port Number Registry: port 1701
- RFC 2661: Layer Two Tunneling Protocol "L2TP"
- RFC 3193: Securing L2TP using IPsec
- Microsoft Learn: Service overview and network port requirements for Windows
- Microsoft Tech Community: PPTP and L2TP deprecation: A new era of secure connectivity
- Microsoft Learn: Configure VPN protocols in Routing and Remote Access on Windows Server
- RFC 7296: Internet Key Exchange Protocol Version 2 (IKEv2)
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 1701 is not guaranteed to be L2TP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).