Skip to main content

Port Details

Port
515
Transport
TCP
Service
LPD
IANA service name
printer
Range
System port (0-1023)

Security Exposure

RFC 1179 states that security issues are not discussed in the memo and describes LPR as a TCP-based protocol. Because the memo specifies no security mechanisms, access to port 515 has to be controlled through network filtering.

Hardening

  • +Disable LPD on printers and print servers where IPP or vendor-supported protocols are available.
  • +Allow TCP 515 only from print servers or approved client subnets.
  • +Place printers on a dedicated network segment without inbound internet access.
  • +Keep printer firmware updated and change default administrative passwords.

Monitoring

Inventory hosts listening on TCP 515 and alert on new ones. Watch for 515 connections from outside approved client ranges.

Tools for Auditing and Monitoring LPD

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Nessus

Commercial
Vulnerability Scanning

Tenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.

LicenseProprietary
PlatformLinux, Windows, Web

OPENVAS

Free / Commercial
Vulnerability Scanning

Full-featured vulnerability scanner for identifying security flaws, missing patches, and weak configs across network hosts.

LicenseGPL-2.0-only (C scanner); GPL-2.0-or-later WITH OpenSSL-exception (Rust)
PlatformLinux

Frequently Asked Questions

What is port 515 used for?→

It is the LPD print spooler port defined in RFC 1179. Microsoft lists TCP 515 for the LPD service of the TCP/IP Print Server.

Is LPD secure?→

RFC 1179 states that security issues are not discussed in the memo. Access should be limited by network filtering, or LPD replaced with IPP over HTTPS (ipps).

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 515 is not guaranteed to be LPD. Exploited-in-the-wild data from the CISA KEV catalog (CC0).