Port 179: Border Gateway Protocol
TCP port 179 is used by the Border Gateway Protocol (BGP), the inter-autonomous-system routing protocol defined in RFC 4271, which states that BGP listens on TCP port 179. Routers open BGP sessions with configured neighbors on this port to exchange routing information.
Port Details
Security Exposure
RFC 7454 warns that a BGP speaker without ACLs can be attacked simply by sending it a high volume of connection requests. Spoofed TCP RST packets can bring down a peering, and an attacker in a man-in-the-middle position may inject packets into the session to manipulate routing.
Hardening
- +Apply a control-plane ACL that drops TCP 179 packets from addresses that are not configured BGP neighbors (RFC 7454).
- +Protect sessions with the TCP Authentication Option (RFC 5925), or MD5 where TCP-AO is not available.
- +Enable GTSM (TTL security, RFC 5082) on directly connected peers.
- +Set a maximum prefix limit on every peering, as RFC 7454 recommends.
Monitoring
Log BGP session state changes and authentication failures. Alert on connection attempts to TCP 179 from non-neighbor addresses and on peers that reach their prefix limit.
BGP Vulnerabilities
3 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2010-3035 | Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability | - | 7.5 | 5.7% | KEV | 2010-08-30 |
| CVE-2009-2055 | Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability | - | 5.9 | 3.3% | KEV | 2009-08-19 |
| CVE-2017-12319 | Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability | - | 5.9 | 5.2% | KEV | 2018-03-27 |
Tools for Auditing and Monitoring BGP
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Wireshark
Open SourceNetwork packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.
Related Tool Categories
Frequently Asked Questions
Is BGP TCP or UDP?→
BGP runs over TCP. RFC 4271 states that BGP listens on TCP port 179, even though IANA also lists UDP and SCTP entries.
How are BGP sessions protected?→
RFC 7454 recommends ACLs that block TCP 179 from non-neighbors, TCP-AO (preferred over MD5) for session authentication, and GTSM to reject packets that did not come from a directly connected peer.
Which vulnerabilities affect the service on port 179?→
This database lists 3 CVEs related to BGP, 3 of them confirmed as exploited by CISA. Examples: CVE-2010-3035, CVE-2009-2055, CVE-2017-12319.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 179 is not guaranteed to be BGP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).