Skip to main content

Port Details

Port
4500
Transport
UDP
Service
IPsec NAT-T
IANA service name
ipsec-nat-t
Range
User port (1024-49151)
Related ports

Security Exposure

UDP 500 and 4500 are where IPsec VPN gateways accept IKE traffic from the internet. Shadowserver reports hosts with a vulnerable IKE service accessible on the internet and has tagged WatchGuard Firebox iked flaws CVE-2025-9242 and CVE-2025-14733; CISA lists both in its Known Exploited Vulnerabilities catalog.

Hardening

  • +Patch VPN gateway firmware promptly, prioritizing IKE vulnerabilities listed in CISA KEV.
  • +Allow UDP 500 and 4500 only on hosts that terminate IPsec, and drop them elsewhere.

Monitoring

Log IKE negotiation failures and unexpected IKE traffic to hosts that are not VPN gateways. Shadowserver vulnerable ISAKMP reports flag gateways with known flaws.

IPsec NAT-T Vulnerabilities

7 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-33824
Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
Microsoft9.81.6%KEV2026-04-14
CVE-2025-14733
WatchGuard Firebox iked Out of Bounds Write Vulnerability
WatchGuard9.326.5%KEV2025-12-19
CVE-2025-9242
WatchGuard Firebox iked Out of Bounds Write Vulnerability
WatchGuard9.391.3%KEV2025-09-17
CVE-2016-6415
Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability
-7.587.7%KEV2016-09-19
CVE-2018-0158
Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability
-8.67.2%KEV2018-03-28
CVE-2017-12237
Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability
-7.57.1%KEV2017-09-28
CVE-2018-0159
Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability
-7.56.9%KEV2018-03-28

Tools for Auditing and Monitoring IPsec NAT-T

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

OPENVAS

Free / Commercial
Vulnerability Scanning

Full-featured vulnerability scanner for identifying security flaws, missing patches, and weak configs across network hosts.

LicenseGPL-2.0-only (C scanner); GPL-2.0-or-later WITH OpenSSL-exception (Rust)
PlatformLinux

Nessus

Commercial
Vulnerability Scanning

Tenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.

LicenseProprietary
PlatformLinux, Windows, Web

Frequently Asked Questions

What is the difference between UDP 500 and UDP 4500?→

IKE normally runs on UDP 500. When NAT is detected, IKE and ESP traffic move to UDP 4500, as described in RFC 7296 and RFC 3948.

Is port 4500 TCP or UDP?→

IPsec NAT traversal uses UDP 4500. IANA also registers TCP 4500 under the same name.

Do IPsec VPNs need port 4500 open?→

Gateways that serve clients or peers behind NAT need UDP 4500 in addition to UDP 500 and should limit it to VPN endpoints.

Which vulnerabilities affect the service on port 4500?→

This database lists 7 CVEs related to IPsec NAT-T, 7 of them confirmed as exploited by CISA. Examples: CVE-2026-33824, CVE-2025-14733, CVE-2025-9242, CVE-2016-6415.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 4500 is not guaranteed to be IPsec NAT-T. Exploited-in-the-wild data from the CISA KEV catalog (CC0).