Reason for ports showing as open on port scans (7999, 8010, 8444)

Jimmy Cao 0 Reputation points
2024-07-09T14:34:08.7833333+00:00

Our company conducts a vulnerability scan and observes ports 7999, 8010, and 8444 open to any. We're aware that there are some ports required for Azure infrastructure to work correctly. Are these some of those ports? We've read that they are used for health probes, is there any way for us to confirm that these are the ports being used from the Azure console page

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,543 questions
Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,472 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. ChaitanyaNaykodi-MSFT 26,201 Reputation points Microsoft Employee
    2024-07-09T21:18:56.9666667+00:00

    @Jimmy Cao

    Thank you for reaching out. Yes, port number 7999 and 8444 is used for Azure infrastructure communication. I am confirming the information regarding port 8010 with the team internally and will get back to you shortly.

    As documented here They're protected (locked down) by Azure certificates. Without proper certificates, external entities, including the customers of those gateways, won't be able to cause any effect on those endpoints. The public endpoints are periodically scanned by Azure security audit.

    Update 07/11: Based on our private conversation here. We are disregarding the information regarding port 8010.

    For community benefit port 8010 should not be open on Azure VPN Gateway.

    Thank you!

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.