Port 500: Internet Key Exchange for IPsec
UDP 500 is where IKE negotiates security associations for IPsec VPNs. RFC 7296 says IKE normally listens and sends on UDP 500, and may also use UDP 4500 when NAT traversal is in use. Site-to-site and remote-access VPN gateways, as well as Windows IPsec, use it.
Port Details
Security Exposure
IKE has to be reachable from peers, so VPN gateways expose it to the internet by design. CISA and NSA describe remote-access VPN servers as entry points that malicious actors exploit for credential harvesting, remote code execution and session hijacking.
Hardening
- +Restrict UDP 500 and 4500 to known peer addresses for site-to-site tunnels where possible.
- +Allow only strong, approved cryptographic protocols, algorithms, and authentication credentials, as the NSA and CISA VPN hardening guidance advises.
- +Patch VPN gateways promptly, and review credentials and logs after patching a vulnerability known to have been exploited.
- +Restrict external access to the VPN device to reduce its attack surface.
Monitoring
Enable local and remote logging of VPN user activity, as the NSA and CISA guidance recommends, including IKE negotiation failures and tunnel establishment. Track gateway firmware versions against vendor advisories.
IKE (ISAKMP) Vulnerabilities
7 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-33824 | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability | Microsoft | 9.8 | 1.6% | KEV | 2026-04-14 |
| CVE-2025-14733 | WatchGuard Firebox iked Out of Bounds Write Vulnerability | WatchGuard | 9.3 | 26.5% | KEV | 2025-12-19 |
| CVE-2025-9242 | WatchGuard Firebox iked Out of Bounds Write Vulnerability | WatchGuard | 9.3 | 91.3% | KEV | 2025-09-17 |
| CVE-2016-6415 | Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability | - | 7.5 | 87.7% | KEV | 2016-09-19 |
| CVE-2018-0158 | Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability | - | 8.6 | 7.2% | KEV | 2018-03-28 |
| CVE-2017-12237 | Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability | - | 7.5 | 7.1% | KEV | 2017-09-28 |
| CVE-2018-0159 | Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability | - | 7.5 | 6.9% | KEV | 2018-03-28 |
Tools for Auditing and Monitoring IKE (ISAKMP)
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Suricata
Open SourceHigh-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.
Related Tool Categories
Frequently Asked Questions
Is port 500 TCP or UDP?→
IKE runs over UDP 500. IANA also lists isakmp on TCP 500, but RFC 7296 describes IKE listening on UDP port 500 and UDP 4500.
Why is UDP 4500 used together with 500?→
UDP 4500 carries IKE and encapsulated IPsec traffic when NAT devices sit between the peers, as described in RFC 7296 and RFC 3947.
Which vulnerabilities affect the service on port 500?→
This database lists 7 CVEs related to IKE (ISAKMP), 7 of them confirmed as exploited by CISA. Examples: CVE-2026-33824, CVE-2025-14733, CVE-2025-9242, CVE-2016-6415.
Sources
- IANA Service Name and Port Number Registry: port 500
- RFC 7296: Internet Key Exchange Protocol Version 2 (IKEv2)
- RFC 3947: Negotiation of NAT-Traversal in the IKE
- CISA: CISA and NSA Release Guidance on Selecting and Hardening VPNs
- Microsoft Learn: Service overview and network port requirements for Windows
- SecurityWeek: NSA, CISA Issue Guidance on Selecting and Securing VPNs
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 500 is not guaranteed to be IKE (ISAKMP). Exploited-in-the-wild data from the CISA KEV catalog (CC0).