Skip to main content

Port Details

Port
8834
Transport
TCP
Service
Nessus
IANA service name
unassigned
Range
User port (1024-49151)
Related ports

Security Exposure

Tenable's deployment guidance notes that Nessus only requires a connection to Tenable Security Center for operational use and suggests restricting interface access to that server where possible. By default Nessus uses a certificate signed by its own Nessus Certification Authority, which browsers report as untrusted until it is replaced or the CA is trusted.

Hardening

  • +Restrict inbound 8834 to Tenable Security Center, administrator workstations, and, for Nessus Manager, the agent networks.
  • +Replace the default certificate with one from a trusted CA, as Tenable recommends.
  • +Use strong, unique passwords for Nessus accounts and keep the number of administrator accounts small.
  • +Where Tenable Security Center is used, integrate it with a PAM solution so scans draw credentials from a central password store.

Monitoring

Log and review logins to the Nessus interface, especially failed attempts and logins from unexpected addresses. Alert on any 8834 exposure found by external attack surface scans.

Tools for Auditing and Monitoring Nessus

Censys

Freemium
Open Source Intelligence Tools

Internet scan and host reconnaissance platform that maps exposed services, certificates, and infrastructure across the global web.

LicenseProprietary
PlatformWeb

Nessus

Commercial
Vulnerability Scanning

Tenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.

LicenseProprietary
PlatformLinux, Windows, Web

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Frequently Asked Questions

What is port 8834?→

It is the default port for the Tenable Nessus web interface and API. Nessus Agents also use 8834 to reach Nessus Manager.

Can I change the Nessus port?→

Yes. The Nessus web server port is the xmlrpc_listen_port advanced setting, which defaults to 8834.

Why does my browser warn about the certificate on port 8834?→

Nessus ships with a default certificate signed by the Nessus Certification Authority, which browsers do not trust. Tenable documents how to upload a custom server certificate or install the Nessus root CA to remove the warning.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 8834 is not guaranteed to be Nessus. Exploited-in-the-wild data from the CISA KEV catalog (CC0).