Port 5432: PostgreSQL

What it is, why it matters and how to restrict it.

The default port of PostgreSQL. Reaching it from outside is a common goal for attackers, so it should be open only to the hosts that need it.

Secure it

PostgreSQL listens on localhost by default. The listen_addresses setting in postgresql.conf opens it to other interfaces, and pg_hba.conf decides which hosts and users may connect. Both layers should agree with your firewall.

Allow only one address on Linux

sudo iptables -I INPUT 1 -p tcp --dport 5432 -j DROP
sudo iptables -I INPUT 1 -p tcp -s 203.0.113.5 --dport 5432 -j ACCEPT

The drop rule goes in first and the allow rule is inserted above it, so 203.0.113.5 is matched first. Replace it with your own address. With ufw, the equivalent allow rule is:

sudo ufw allow from 203.0.113.5 to any port 5432 proto tcp

Check from outside

nc -vz SERVER_IP 5432

Run it from an allowed address and from another one. A connection should succeed from the first and fail or time out from the second. Build custom rules with allow a port from specific IPs, or see all common ports.

FAQ

What is port 5432 used for?

Port 5432 is the default TCP port of PostgreSQL.

Should port 5432 be open to the internet?

Usually not. Keep it on localhost, behind a VPN, or limited to specific source IPs.

How do I block port 5432 for everyone except one IP?

Add an ACCEPT rule for that address, then a DROP rule for the port below it. The commands above do this in the correct order.

© PacketUtils. Tools run in your browser. Review every command before using it in production.HomeAboutContactPrivacy Policy