Port 9443: Alternate HTTPS port, default for the Portainer web UI
IANA registers 9443 as tungsten-https (WSO2 Tungsten HTTPS). Portainer Server, a container management UI, exposes its interface over 9443 by default with a self-signed certificate, and an optional TCP tunnel server for Edge agents on 8000.
Port Details
Security Exposure
Portainer's standard installation mounts the Docker socket into the container, giving the Portainer server control of the Docker daemon. Docker's security documentation states that only trusted users should be allowed to control the Docker daemon. Management interfaces on 9443 fall under CISA BOD 23-02, which calls for removing them from the internet or protecting them with separate access controls.
Hardening
- +Restrict 9443 to administrator networks or put it behind an authenticated access proxy.
- +Keep the default setup token requirement for Portainer first-time setup and complete setup promptly.
- +Replace the default self-signed certificate with a trusted one.
- +Identify any other product listening on 9443 and patch it on the vendor's schedule.
Monitoring
Review authentication logs for the service on 9443 and alert on new administrator accounts or logins from unexpected addresses. Scan periodically for external exposure of the port.
Tools for Auditing and Monitoring HTTPS alternate (Portainer)
Falco
Open SourceCloud-native runtime security engine that monitors Linux kernel system calls to detect anomalous behavior in containers.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Nuclei
Free / CommercialFast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.
Related Tool Categories
CSPM scanners, container and Kubernetes policy engines, and cloud configuration auditing tools.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Infrastructure scanners, CVE audit engines, container image inspectors, and exposure management platforms.
Frequently Asked Questions
What runs on port 9443?→
Portainer uses it by default for its web UI. IANA's registration is tungsten-https.
Is port 9443 the same as 443?→
Both carry HTTPS in the Portainer case. 443 is the standard HTTPS port, while 9443 is the port Portainer chooses for its UI.
Should Portainer on 9443 be exposed to the internet?→
It should be restricted, because Portainer manages the Docker host through the Docker socket and Docker states that only trusted users should control the daemon.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 9443 is not guaranteed to be HTTPS alternate (Portainer). Exploited-in-the-wild data from the CISA KEV catalog (CC0).