Skip to main content

Port Details

Port
3478
Transport
UDP / TCP
Service
STUN/TURN
IANA service name
stun, turn, stun-behavior
Range
User port (1024-49151)
Related ports
5349

Security Exposure

Shadowserver lists STUN as a UDP service that can be abused as an amplifier in reflected denial of service attacks, though with a modest average amplification factor of about 4. A TURN server relays traffic on behalf of clients, so RFC 8656 requires clients to authenticate, typically with STUN's long-term credential mechanism. A TURN relay with weak or shared credentials can be used by unauthorized parties to relay traffic.

Hardening

  • +Require authentication for TURN allocations using the long-term credential mechanism or third-party authorization (RFC 7635).
  • +Restrict the peer addresses a TURN server will relay to; RFC 8656 allows servers to reject disallowed XOR-PEER-ADDRESS values with 403 (Forbidden).
  • +Offer STUN and TURN over TLS or DTLS on 5349 where clients support it.

Monitoring

Log TURN allocation requests and 401 authentication failures, and watch for allocations whose peer permissions target internal address ranges. Flow data showing large outbound UDP responses from 3478 can indicate reflection abuse.

Tools for Auditing and Monitoring STUN/TURN

Wireshark

Open Source
Network Monitoring Tools

Network packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.

LicenseGPL-2.0-or-later
PlatformWindows, macOS, Linux, BSD

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Frequently Asked Questions

Is port 3478 TCP or UDP?→

Both. RFC 8489 sets 3478 as the default STUN port for TCP and UDP, and IANA also registers TURN on 3478 for both transports.

What is the difference between STUN and TURN?→

STUN lets a client learn its public address and port behind NAT. TURN goes further and relays traffic through the server, which is why RFC 8656 requires client authentication.

Which port does STUN over TLS use?→

RFC 8489 sets 5349 as the default port for STUN over TLS and STUN over DTLS.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 3478 is not guaranteed to be STUN/TURN. Exploited-in-the-wild data from the CISA KEV catalog (CC0).