Skip to main content

Port Details

Port
179
Transport
TCP
Service
BGP
IANA service name
bgp
Range
System port (0-1023)

Security Exposure

RFC 7454 warns that a BGP speaker without ACLs can be attacked simply by sending it a high volume of connection requests. Spoofed TCP RST packets can bring down a peering, and an attacker in a man-in-the-middle position may inject packets into the session to manipulate routing.

Hardening

  • +Apply a control-plane ACL that drops TCP 179 packets from addresses that are not configured BGP neighbors (RFC 7454).
  • +Protect sessions with the TCP Authentication Option (RFC 5925), or MD5 where TCP-AO is not available.
  • +Enable GTSM (TTL security, RFC 5082) on directly connected peers.
  • +Set a maximum prefix limit on every peering, as RFC 7454 recommends.

Monitoring

Log BGP session state changes and authentication failures. Alert on connection attempts to TCP 179 from non-neighbor addresses and on peers that reach their prefix limit.

BGP Vulnerabilities

3 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2010-3035
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
-7.55.7%KEV2010-08-30
CVE-2009-2055
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
-5.93.3%KEV2009-08-19
CVE-2017-12319
Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability
-5.95.2%KEV2018-03-27

Tools for Auditing and Monitoring BGP

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Wireshark

Open Source
Network Monitoring Tools

Network packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.

LicenseGPL-2.0-or-later
PlatformWindows, macOS, Linux, BSD

Frequently Asked Questions

Is BGP TCP or UDP?→

BGP runs over TCP. RFC 4271 states that BGP listens on TCP port 179, even though IANA also lists UDP and SCTP entries.

How are BGP sessions protected?→

RFC 7454 recommends ACLs that block TCP 179 from non-neighbors, TCP-AO (preferred over MD5) for session authentication, and GTSM to reject packets that did not come from a directly connected peer.

Which vulnerabilities affect the service on port 179?→

This database lists 3 CVEs related to BGP, 3 of them confirmed as exploited by CISA. Examples: CVE-2010-3035, CVE-2009-2055, CVE-2017-12319.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 179 is not guaranteed to be BGP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).