Port 27017: MongoDB
TCP 27017 is the port for MongoDB. Never on the internet; enable authentication and bind to a private address.
| Service | MongoDB |
|---|---|
| Protocol | TCP |
| Exposure risk | High: do not expose to the internet |
| Range | Registered (1024–49151) |
What port 27017 does
The default port for MongoDB. Before version 3.6, MongoDB bound to all interfaces with no authentication by default, which led to tens of thousands of wiped and ransomed databases.
Should port 27017 be open?
Never on the internet; enable authentication and bind to a private address.
Find what's listening on port 27017
- Linux:
sudo ss -tulpn | grep :27017 - macOS:
sudo lsof -nP -i :27017 - Windows:
netstat -ano | findstr :27017, then look up the PID in Task Manager.
Open or block it in a firewall
- ufw:
sudo ufw allow 27017/tcp(ordeny) - firewalld:
sudo firewall-cmd --add-port=27017/tcp --permanent && sudo firewall-cmd --reload - Windows:
New-NetFirewallRule -DisplayName "Port 27017" -Direction Inbound -Protocol TCP -LocalPort 27017 -Action Allow
Port assignment per the IANA Service Name and Transport Protocol Port Number Registry. Test several ports at once with the port scanner, or any port with the open port checker.
Questions about port 27017
What is port 27017 used for?
MongoDB. The default port for MongoDB. Before version 3.6, MongoDB bound to all interfaces with no authentication by default, which led to tens of thousands of wiped and ransomed databases.
Is port 27017 TCP or UDP?
TCP. MongoDB uses TCP port 27017.
Is it safe to open port 27017?
High: do not expose to the internet. Never on the internet; enable authentication and bind to a private address.
How do I check if port 27017 is open?
Use the checker on this page: it connects to your host on TCP 27017 from the internet. Locally, run
nc -vz host 27017 (macOS/Linux) or Test-NetConnection host -Port 27017 (PowerShell). To see what is listening on your own machine, run ss -tulpn | grep :27017 (Linux) or netstat -ano | findstr :27017 (Windows).