Port 3478: Session Traversal Utilities for NAT and Traversal Using Relays around NAT
Port 3478 is the default for STUN requests over UDP and TCP (RFC 8489) and is registered for TURN, which relays traffic for clients that cannot connect directly (RFC 8656). RFC 8656 names WebRTC and SIP as uses of TURN relays. STUN and TURN over TLS or DTLS use port 5349.
Port Details
Security Exposure
Shadowserver lists STUN as a UDP service that can be abused as an amplifier in reflected denial of service attacks, though with a modest average amplification factor of about 4. A TURN server relays traffic on behalf of clients, so RFC 8656 requires clients to authenticate, typically with STUN's long-term credential mechanism. A TURN relay with weak or shared credentials can be used by unauthorized parties to relay traffic.
Hardening
- +Require authentication for TURN allocations using the long-term credential mechanism or third-party authorization (RFC 7635).
- +Restrict the peer addresses a TURN server will relay to; RFC 8656 allows servers to reject disallowed XOR-PEER-ADDRESS values with 403 (Forbidden).
- +Offer STUN and TURN over TLS or DTLS on 5349 where clients support it.
Monitoring
Log TURN allocation requests and 401 authentication failures, and watch for allocations whose peer permissions target internal address ranges. Flow data showing large outbound UDP responses from 3478 can indicate reflection abuse.
Tools for Auditing and Monitoring STUN/TURN
Wireshark
Open SourceNetwork packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Related Tool Categories
Frequently Asked Questions
Is port 3478 TCP or UDP?→
Both. RFC 8489 sets 3478 as the default STUN port for TCP and UDP, and IANA also registers TURN on 3478 for both transports.
What is the difference between STUN and TURN?→
STUN lets a client learn its public address and port behind NAT. TURN goes further and relays traffic through the server, which is why RFC 8656 requires client authentication.
Which port does STUN over TLS use?→
RFC 8489 sets 5349 as the default port for STUN over TLS and STUN over DTLS.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 3478 is not guaranteed to be STUN/TURN. Exploited-in-the-wild data from the CISA KEV catalog (CC0).