Port 515: Line Printer Daemon protocol
TCP 515 is where a line printer daemon (LPD) listens for print jobs under RFC 1179. The Windows TCP/IP Print Server service uses LPD on TCP 515 to receive documents from LPR clients. RFC 1179 specifies that clients connect from source ports 721 to 731.
Port Details
Security Exposure
RFC 1179 states that security issues are not discussed in the memo and describes LPR as a TCP-based protocol. Because the memo specifies no security mechanisms, access to port 515 has to be controlled through network filtering.
Hardening
- +Disable LPD on printers and print servers where IPP or vendor-supported protocols are available.
- +Allow TCP 515 only from print servers or approved client subnets.
- +Place printers on a dedicated network segment without inbound internet access.
- +Keep printer firmware updated and change default administrative passwords.
Monitoring
Inventory hosts listening on TCP 515 and alert on new ones. Watch for 515 connections from outside approved client ranges.
Tools for Auditing and Monitoring LPD
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Nessus
CommercialTenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.
OPENVAS
Free / CommercialFull-featured vulnerability scanner for identifying security flaws, missing patches, and weak configs across network hosts.
Related Tool Categories
Frequently Asked Questions
What is port 515 used for?→
It is the LPD print spooler port defined in RFC 1179. Microsoft lists TCP 515 for the LPD service of the TCP/IP Print Server.
Is LPD secure?→
RFC 1179 states that security issues are not discussed in the memo. Access should be limited by network filtering, or LPD replaced with IPP over HTTPS (ipps).
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 515 is not guaranteed to be LPD. Exploited-in-the-wild data from the CISA KEV catalog (CC0).