Port 4500: IPsec NAT Traversal (UDP-encapsulated ESP and IKE)
UDP 4500 carries IKE messages and UDP-encapsulated ESP packets when an IPsec peer sits behind NAT (RFC 3948). IKE normally listens and sends on UDP 500, though IKE messages may also be received on UDP 4500 (RFC 7296). IPsec VPN gateways that serve peers behind NAT listen on both ports.
Port Details
Security Exposure
UDP 500 and 4500 are where IPsec VPN gateways accept IKE traffic from the internet. Shadowserver reports hosts with a vulnerable IKE service accessible on the internet and has tagged WatchGuard Firebox iked flaws CVE-2025-9242 and CVE-2025-14733; CISA lists both in its Known Exploited Vulnerabilities catalog.
Hardening
- +Patch VPN gateway firmware promptly, prioritizing IKE vulnerabilities listed in CISA KEV.
- +Allow UDP 500 and 4500 only on hosts that terminate IPsec, and drop them elsewhere.
Monitoring
Log IKE negotiation failures and unexpected IKE traffic to hosts that are not VPN gateways. Shadowserver vulnerable ISAKMP reports flag gateways with known flaws.
IPsec NAT-T Vulnerabilities
7 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-33824 | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability | Microsoft | 9.8 | 1.6% | KEV | 2026-04-14 |
| CVE-2025-14733 | WatchGuard Firebox iked Out of Bounds Write Vulnerability | WatchGuard | 9.3 | 26.5% | KEV | 2025-12-19 |
| CVE-2025-9242 | WatchGuard Firebox iked Out of Bounds Write Vulnerability | WatchGuard | 9.3 | 91.3% | KEV | 2025-09-17 |
| CVE-2016-6415 | Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability | - | 7.5 | 87.7% | KEV | 2016-09-19 |
| CVE-2018-0158 | Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability | - | 8.6 | 7.2% | KEV | 2018-03-28 |
| CVE-2017-12237 | Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability | - | 7.5 | 7.1% | KEV | 2017-09-28 |
| CVE-2018-0159 | Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability | - | 7.5 | 6.9% | KEV | 2018-03-28 |
Tools for Auditing and Monitoring IPsec NAT-T
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
OPENVAS
Free / CommercialFull-featured vulnerability scanner for identifying security flaws, missing patches, and weak configs across network hosts.
Nessus
CommercialTenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.
Related Tool Categories
Frequently Asked Questions
What is the difference between UDP 500 and UDP 4500?→
IKE normally runs on UDP 500. When NAT is detected, IKE and ESP traffic move to UDP 4500, as described in RFC 7296 and RFC 3948.
Is port 4500 TCP or UDP?→
IPsec NAT traversal uses UDP 4500. IANA also registers TCP 4500 under the same name.
Do IPsec VPNs need port 4500 open?→
Gateways that serve clients or peers behind NAT need UDP 4500 in addition to UDP 500 and should limit it to VPN endpoints.
Which vulnerabilities affect the service on port 4500?→
This database lists 7 CVEs related to IPsec NAT-T, 7 of them confirmed as exploited by CISA. Examples: CVE-2026-33824, CVE-2025-14733, CVE-2025-9242, CVE-2016-6415.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 4500 is not guaranteed to be IPsec NAT-T. Exploited-in-the-wild data from the CISA KEV catalog (CC0).