Skip to main content
Curated port reference

Port 4789: Docker Swarm VXLAN / VXLAN (TCP reference coverage)

Port 4789 supports Docker Swarm VXLAN and VXLAN (TCP reference coverage) across distinct transports. Review each protocol before writing firewall or monitoring policy.

4789UDP

Docker Swarm VXLAN

Default VXLAN data path for Docker Swarm overlay networks.

Typical use

Container traffic traversing between swarm nodes on overlay networks.

Traffic direction

Cluster internal

Security considerations

Docker explicitly recommends limiting this unauthenticated VXLAN path to trusted networks and never opening it at the perimeter.

4789TCP

VXLAN (TCP reference coverage)

VXLAN (TCP reference coverage) is documented as a network service convention for port 4789 over TCP.

Typical use

Use this reference entry when identifying or validating systems documented to use 4789/TCP.

Traffic direction

Varies

Security considerations

Confirm the listening process and current vendor documentation before permitting traffic; a listed convention does not prove the active service or its security posture.