Network port detail · TCP/UDP

862

Twamp-control
Protocol(s)
TCP/UDP
Range
System (0-1023)
Reference
[RFC5357] (tcp) / [RFC8545] (udp)

Summary

// if you see it open
TWAMP exchanges can support reconnaissance, and a UDP-based reflector could in principle be abused in reflection/amplification scenarios if openly exposed. Limit access to known peers; vendor implementations support client-list ACLs (Cisco ip sla server twamp, Juniper rpm twamp server client-list).
// analyst note
An open 862 indicates a TWAMP measurement endpoint (ISP/SLA) — TCP 862 is the control channel; 862/udp is the TWAMP-Test receiver port; limit to known peers.
[ 01 ] — Context

About port 862.

Updated  ·  Confidence: High

Port 862 is a transport split in the live IANA registry (Last Updated 2026-05-29): 862/tcp is registered as twamp-control with the description "TWAMP-Control" and reference [RFC5357], while 862/udp is registered as twamp-test with the description "TWAMP-Test Receiver Port" and reference [RFC8545]; both transports list assignee IESG and contact IETF Chair. TWAMP, the Two-Way Active Measurement Protocol (RFC 5357, October 2008), provides two-way — round-trip — network-performance measurement of delay, jitter, and loss, built atop OWAMP, the One-Way Active Measurement Protocol (RFC 4656, port 861). TWAMP-Control on TCP 862 negotiates test sessions, after which TWAMP-Test exchanges test packets over UDP. The architecture has four logical entities — Control-Client, Server, Session-Sender, and Session-Reflector — commonly merged into a controller/client and a responder/server; per RFC 5357, a client opens a TCP connection to the server on well-known port 862. The UDP side of 862 was changed by RFC 8545 (March 2019), which reallocated UDP ports 861 and 862 while leaving the TCP assignments as they were and updated the assignee and contact to the IESG and IETF Chair; the result is that 862/udp is now twamp-test ("TWAMP-Test Receiver Port"), not twamp-control, because TWAMP-Control requires TCP transport and the optional UDP use is for TWAMP-Test data. Security-wise TWAMP exchanges can support reconnaissance, and a UDP-based reflector could in principle be abused in reflection or amplification scenarios if openly exposed, so access should be limited to known peers; vendor implementations support client-list ACLs. For an analyst, an open 862 indicates a TWAMP measurement endpoint — typically an ISP or carrier probe, an SLA monitor, or a router or switch acting as a TWAMP responder; nmap open-frequency is low.

IANA assignment
862/tcp twamp-control — "TWAMP-Control" [RFC5357]; 862/udp twamp-test — "TWAMP-Test Receiver Port" [RFC8545] (the transports DIFFER); assignee [IESG], contact [IETF_Chair] (updated by RFC 8545) [IANA-assigned, verified live] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023)
Prevalence
low; nmap-services de-facto low [Well-established] — nmap-services file
Related ports
861 (OWAMP-Control tcp / OWAMP-Test udp, RFC 4656 + RFC 8545); TWAMP-Test UDP

Primary use

TWAMP two-way (round-trip) network-performance measurement — delay, jitter, loss (RFC 5357)

[Well-established] — RFC 5357, RFC 8545

Other/unofficial uses

TWAMP Light eliminates the control session (stateless reflector) [Well-established]

Security implications

can support reconnaissance; an exposed UDP reflector could be abused for reflection/amplification — limit to known peers with client-list ACLs

[Well-established/Threat-reported] — Cisco/Juniper TWAMP docs

Typically seen on

ISP/carrier measurement probes, SLA monitors, routers/switches as TWAMP responders (Cisco IOS XE IP SLAs TWAMP Responder; Juniper MX/PTX)

Analyst note
An open 862 indicates a TWAMP measurement endpoint (ISP/SLA) — TCP 862 is the control channel; 862/udp is the TWAMP-Test receiver port; limit to known peers.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
twamp-control TCP twamp-test 0.01%
twamp-control UDP Two-way Active Measurement Protocol (TWAMP) Control 0.00%
IANA name
twamp-control (tcp) / twamp-test (udp)
Transport
TCP+UDP
Range
System (0-1023)
Reference
[RFC5357] (tcp) / [RFC8545] (udp)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.