Port 68: Dynamic Host Configuration Protocol (client port)
UDP port 68 is the DHCP client port. Hosts that obtain addresses dynamically listen on it for DHCPOFFER, DHCPACK, and DHCPNAK replies, which RFC 2131 says servers send to the client port (68). The IANA name bootpc comes from the Bootstrap Protocol client role.
Port Details
Security Exposure
A DHCP client accepts configuration from whichever server answers, because DHCP has no built-in authentication. RFC 2131 warns that false settings such as spoofed routers and name servers let an attacker compromise affected hosts further. RFC 2131 also notes that unauthorized DHCP servers may be easily set up.
Hardening
- +Enable DHCP snooping so that only trusted switch ports can deliver server replies to clients.
- +Segment untrusted devices into separate VLANs to limit how many clients a rogue server can reach.
- +Use static addressing for servers and network infrastructure that do not need DHCP.
- +Keep operating systems and DHCP client software patched.
Monitoring
Compare the router and DNS settings handed to clients with the approved configuration, and alert on DHCP replies from server addresses that are not authorized.
DHCP client Vulnerabilities
1 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2017-12240 | Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability | - | 9.8 | 13.8% | KEV | 2017-09-28 |
Tools for Auditing and Monitoring DHCP client
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Wireshark
Open SourceNetwork packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.
Suricata
Open SourceHigh-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.
Related Tool Categories
Frequently Asked Questions
Is port 68 used by the DHCP server or the client?→
The client. RFC 2131 sends server-to-client DHCP messages to the client port 68, while servers listen on port 67.
Does port 68 need to be open?→
Hosts that get addresses through DHCP must accept replies on UDP 68 from the local DHCP server or relay agent. It has no reason to be reachable from the internet.
Which vulnerabilities affect the service on port 68?→
This database lists 1 CVE related to DHCP client, 1 of them confirmed as exploited by CISA. Examples: CVE-2017-12240.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 68 is not guaranteed to be DHCP client. Exploited-in-the-wild data from the CISA KEV catalog (CC0).