Skip to main content

Port Details

Port
500
Transport
UDP
Service
IKE (ISAKMP)
IANA service name
isakmp
Range
System port (0-1023)
Related ports

Security Exposure

IKE has to be reachable from peers, so VPN gateways expose it to the internet by design. CISA and NSA describe remote-access VPN servers as entry points that malicious actors exploit for credential harvesting, remote code execution and session hijacking.

Hardening

  • +Restrict UDP 500 and 4500 to known peer addresses for site-to-site tunnels where possible.
  • +Allow only strong, approved cryptographic protocols, algorithms, and authentication credentials, as the NSA and CISA VPN hardening guidance advises.
  • +Patch VPN gateways promptly, and review credentials and logs after patching a vulnerability known to have been exploited.
  • +Restrict external access to the VPN device to reduce its attack surface.

Monitoring

Enable local and remote logging of VPN user activity, as the NSA and CISA guidance recommends, including IKE negotiation failures and tunnel establishment. Track gateway firmware versions against vendor advisories.

IKE (ISAKMP) Vulnerabilities

7 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-33824
Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
Microsoft9.81.6%KEV2026-04-14
CVE-2025-14733
WatchGuard Firebox iked Out of Bounds Write Vulnerability
WatchGuard9.326.5%KEV2025-12-19
CVE-2025-9242
WatchGuard Firebox iked Out of Bounds Write Vulnerability
WatchGuard9.391.3%KEV2025-09-17
CVE-2016-6415
Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability
-7.587.7%KEV2016-09-19
CVE-2018-0158
Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability
-8.67.2%KEV2018-03-28
CVE-2017-12237
Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability
-7.57.1%KEV2017-09-28
CVE-2018-0159
Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability
-7.56.9%KEV2018-03-28

Tools for Auditing and Monitoring IKE (ISAKMP)

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Suricata

Open Source
Network Monitoring Tools

High-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.

LicenseGPL-2.0-only
PlatformLinux, FreeBSD, macOS, Windows

Frequently Asked Questions

Is port 500 TCP or UDP?→

IKE runs over UDP 500. IANA also lists isakmp on TCP 500, but RFC 7296 describes IKE listening on UDP port 500 and UDP 4500.

Why is UDP 4500 used together with 500?→

UDP 4500 carries IKE and encapsulated IPsec traffic when NAT devices sit between the peers, as described in RFC 7296 and RFC 3947.

Which vulnerabilities affect the service on port 500?→

This database lists 7 CVEs related to IKE (ISAKMP), 7 of them confirmed as exploited by CISA. Examples: CVE-2026-33824, CVE-2025-14733, CVE-2025-9242, CVE-2016-6415.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 500 is not guaranteed to be IKE (ISAKMP). Exploited-in-the-wild data from the CISA KEV catalog (CC0).