Port 1723: Point-to-Point Tunneling Protocol
TCP 1723 carries the PPTP control connection, while the tunneled PPP data travels in an enhanced GRE encapsulation (IP protocol 47) as described in RFC 2637. PPTP is a legacy remote access VPN protocol. Windows Routing and Remote Access lists PPTP on TCP 1723 together with GRE.
Port Details
Security Exposure
RFC 2637 states that PPTP control channel messages are neither authenticated nor integrity protected and that the GRE tunnel packets are not cryptographically protected. An attacker on the path may therefore hijack the control connection or tamper with PPP negotiations. Microsoft has deprecated PPTP in Windows Server and advises moving to SSTP or IKEv2.
Hardening
- +Retire PPTP VPN access and migrate users to IKEv2 or SSTP.
- +Close TCP 1723 and GRE (IP protocol 47) at the perimeter once PPTP is no longer in use.
- +Keep PPTP disabled on new Windows Server 2025 RRAS installations, which no longer accept PPTP connections by default.
- +Where PPTP must remain for a short transition, restrict TCP 1723 to known client address ranges.
Monitoring
Alert on inbound TCP 1723 connections and GRE traffic to hosts that are not approved VPN servers. On remaining PPTP servers, log and review authentication failures.
Tools for Auditing and Monitoring PPTP
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Wireshark
Open SourceNetwork packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Related Tool Categories
Frequently Asked Questions
Is PPTP secure?→
RFC 2637 notes that the PPTP control channel lacks authentication and integrity protection and that GRE tunnel packets are not cryptographically protected. Microsoft has deprecated PPTP and recommends SSTP or IKEv2.
Which ports does PPTP need?→
PPTP uses TCP 1723 for its control connection and GRE (IP protocol 47) for tunneled data. GRE is an IP protocol, not a TCP or UDP port.
Should port 1723 be open?→
Only on a server that still terminates PPTP. Microsoft advises migrating away from PPTP, after which TCP 1723 and GRE can be closed.
Sources
- IANA Service Name and Transport Protocol Port Number Registry: port 1723
- RFC 2637: Point-to-Point Tunneling Protocol (PPTP)
- Microsoft Learn: Service overview and network port requirements for Windows
- Microsoft Tech Community: PPTP and L2TP deprecation: A new era of secure connectivity
- Microsoft Learn: Configure VPN protocols in Routing and Remote Access on Windows Server
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 1723 is not guaranteed to be PPTP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).