Port 51820: WireGuard

UDP 51820 is the port for WireGuard VPN. Designed to be exposed.

Port 51820 at a glance
ServiceWireGuard VPN
ProtocolUDP
Exposure riskLow: normally safe to expose
RangeDynamic / private (49152–65535)

Port 51820 is UDP-only. UDP has no handshake, so no online checker can reliably tell open from filtered; test with the service's own client.

What port 51820 does

WireGuard's conventional listen port (UDP). WireGuard doesn't answer unauthenticated packets, so it is invisible to scans, which also means a TCP checker can't confirm it; test with a client handshake.

Should port 51820 be open?

Designed to be exposed.

Find what's listening on port 51820

  • Linux: sudo ss -tulpn | grep :51820
  • macOS: sudo lsof -nP -i :51820
  • Windows: netstat -ano | findstr :51820, then look up the PID in Task Manager.

Open or block it in a firewall

  • ufw: sudo ufw allow 51820/udp (or deny)
  • firewalld: sudo firewall-cmd --add-port=51820/udp --permanent && sudo firewall-cmd --reload
  • Windows: New-NetFirewallRule -DisplayName "Port 51820" -Direction Inbound -Protocol UDP -LocalPort 51820 -Action Allow

Port assignment per the IANA Service Name and Transport Protocol Port Number Registry. Test several ports at once with the port scanner, or any port with the open port checker.

Questions about port 51820

What is port 51820 used for?
WireGuard VPN. WireGuard's conventional listen port (UDP). WireGuard doesn't answer unauthenticated packets, so it is invisible to scans, which also means a TCP checker can't confirm it; test with a client handshake.
Is port 51820 TCP or UDP?
UDP. WireGuard uses UDP port 51820.
Is it safe to open port 51820?
Low: normally safe to expose. Designed to be exposed.
How do I check if port 51820 is open?
Port 51820 is UDP-only, which has no handshake, so an online TCP checker can't confirm it. Use the service's own client to test, and check what is listening locally with ss -ulpn | grep :51820 (Linux) or netstat -ano | findstr :51820 (Windows).

← Port 32400 (Plex)