Network port detail · TCP/UDP

320

Ptp-general
Protocol(s)
TCP/UDP
Range
System (0-1023)

Summary

// typical exposure
Internal-only — PTP is a low-latency, hardware-timestamped time-synchronization protocol built for internal OT/telecom/industrial LANs, documented as vulnerable to stealthy sync-degradation attacks with only partial mitigations, so it should never be exposed to the public internet.
// if you see it open
Peer-reviewed literature documents that PTP time-sync infrastructure is vulnerable to attacks that can stealthily degrade clock accuracy or disrupt synchronization, and that existing PTP security extensions only partially mitigate this. Despite dual TCP/UDP IANA registration, operational PTP traffic runs almost entirely over UDP or Layer-2 Ethernet for hardware-timestamping latency reasons, so TCP/320 activity does not match documented normal PTP behavior. No port-320-specific CVE or exploit was identified in this pass.
[ 01 ] — Context

About port 320/tcp.

Updated  ·  Confidence: Medium

Port 320/tcp carries ptp-general, IANA's dual-registered (TCP and UDP) channel for Precision Time Protocol (PTP, IEEE 1588) general messages; it should stay on internal, trusted OT/telecom networks rather than be exposed to the public internet.

IANA's Service Names and Port Numbers registry lists 320 as ptp-general ("PTP General"), assigned to Kang_Lee, registered 2010-07-27, with an identical row for UDP/320 confirming true dual registration. The Reference column is blank — the assignment cites a named contact rather than an RFC, so no IANA RFC reference is reported.

PTP's "general" category covers Announce, Follow_Up, management, and signaling messages, distinct from the time-critical Sync/Delay_Req exchanges carried on the paired port 319 (ptp-event). PTP is deployed for sub-microsecond clock synchronization in telecom, power-grid/smart-grid, financial-exchange, and industrial-automation environments.

Despite IANA registering ptp-general for both TCP and UDP, real-world PTP traffic runs almost entirely over UDP (or raw Ethernet in some profiles) to preserve the low-latency hardware timestamping the protocol depends on; TCP/320 traffic is not a documented normal pattern, so a responsive TCP/320 host is unusual on its own terms even where PTP is legitimately deployed.

IANA assignment
ptp-general — "PTP General"; reference blank (named contact [Kang_Lee], not an RFC); registered 2010-07-27; dual-registered 320/tcp + 320/udp, identical entries [Confirmed] — IANA Service Names and Port Numbers Registry
Range class
well-known (0–1023)
Prevalence/scanning stats
Unknown — no dated, sourced count of internet-exposed 320/tcp or 320/udp hosts was found in this pass; not estimated [Unknown]
Related ports
319/udp and 319/tcp (ptp-event, time-critical PTP messages)

Primary use

Precision Time Protocol (IEEE 1588) general (non-time-critical) messages: Announce, Follow_Up, Delay_Resp, Pdelay_Resp_Follow_Up, management/signaling; paired with 319 (ptp-event) for time-critical messages

[Confirmed] — Wikipedia PTP, Wireshark PTP wiki

Security implications

peer-reviewed research documents attacks that can stealthily degrade PTP time-sync accuracy or disrupt clocks/networks, with existing security extensions only partially mitigating; no port-320-specific CVE found

[Confirmed/Unknown] — Springer Cybersecurity journal (2021)

Typically seen on

telecom, OT/industrial, power-grid, and financial-exchange internal networks running PTP grandmaster/slave devices

Transport nuance
TCP is IANA-registered but operational PTP traffic runs almost exclusively over UDP or Layer-2 Ethernet for hardware-timestamping latency reasons; TCP/320 is not a documented normal pattern [Likely] — Wikipedia PTP
Deployment context
telecom, power-grid/smart-grid, financial exchanges, industrial automation requiring sub-microsecond sync, typically on internal/OT networks [Confirmed] — Springer Cybersecurity journal (2021)
[ 02 ] — Context

About port 320/udp.

Updated  ·  Confidence: High

Port 320/udp carries IEEE 1588 Precision Time Protocol (PTP) "general" messages, and it should stay restricted to trusted internal timing networks rather than being exposed to the public internet. It is the companion port to 319/udp: 319 carries timestamp-critical "event" messages (Sync, Delay_Req, Pdelay_Req, Pdelay_Resp), while 320 carries the non-timestamp-critical "general" messages (Announce, Follow_Up, Delay_Resp, Pdelay_Resp_Follow_Up, management, and signaling).

IANA registers 320/udp (and the dual-registered 320/tcp) as ptp-general, "PTP General," assignee [Kang_Lee], registered 2010-07-27. The IANA registry lists no RFC reference for this entry — the Reference column is genuinely blank, not an omission — so this page cites no RFC number for the assignment itself.

PTP synchronizes clocks across a network to sub-microsecond accuracy and is deployed in telecom backhaul (including 5G timing), financial trading (regulatory timestamp accuracy such as MiFID II), industrial automation, power-grid substation protection, and broadcast/AV-over-IP systems. Common implementations include the open-source ptp4l/phc2sys (linuxptp), Meinberg PTP software and grandmaster appliances, Chrony, and PTP stacks built into telecom-grade Cisco, Juniper, and Arista gear.

IANA assignment
ptp-general — "PTP General"; reference blank (no RFC cited in registry); assignee [Kang_Lee]; dual-registered 320/tcp + 320/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023)
Registration date
2010-07-27 [Confirmed] — IANA the IANA Service Name and Transport Protocol Port Number Registry
Prevalence
no verifiable scan-prevalence figure found for this pass [Unknown]
Related ports
319/udp (PTP event messages) [Confirmed]

Primary use

IEEE 1588 Precision Time Protocol (PTP) "general" messages (Announce, Follow_Up, Delay_Resp, Pdelay_Resp_Follow_Up, management/signaling), paired with 319/udp's timestamp-critical "event" messages

[Confirmed] — https://en.wikipedia.org/wiki/Precision_Time_Protocol , https://wiki.wireshark.org/Protocols/ptp

Other/unofficial uses

none beyond PTP identified in this pass [Unknown]

Security implications

PTP is designed for trusted/local timing networks, not public internet exposure; base IEEE 1588 has no default authentication/integrity; RFC 7384 documents spoofing, replay, and rogue-master threats

[Confirmed] — https://datatracker.ietf.org/doc/html/rfc7384

Typically seen on

telecom backhaul (incl. 5G timing), financial trading systems (e.g. MiFID II timestamp accuracy), industrial automation, power-grid substations, broadcast/AV-over-IP

[Likely] — https://en.wikipedia.org/wiki/Precision_Time_Protocol
Common implementations
linuxptp (ptp4l, phc2sys), Meinberg PTP software/appliances, Chrony, telecom-grade Cisco/Juniper/Arista PTP stacks [Likely] — https://wiki.wireshark.org/Protocols/ptp
Analyst note
A responsive 320/udp on a public-facing host is unusual outside dedicated timing infrastructure and warrants checking whether the network segment should be internal-only.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
ptp-general TCP PTP General 0.00%
ptp-general UDP PTP General 0.00%
IANA name
ptp-general
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.