RSYSLOG listening on ephemeral (high) port

Viewed 83

I've been poking around the internet trying to get an answer to this one but so far I've only seen it as "normal" behavior.

I have a fedora 29 host configured to send rsyslog messages over the default 514 port. That works as intented and has been for some time now. I had a client notice that the host would "listen" on an ephemeral port that appears to change with each reboot:

ss -tulnp | grep 46852

udp UNCONN 1536 0 0.0.0.0:468520.0.0.0:* users:(("rsyslogd",pid=676,fd=15))

also:

lsof -i :46852 -P

COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME

rsyslogd 676 root 15u IPv4 24836 0t0 UDP *:46852

Anyone know why rsyslog is doing this? It appears to be default behavior, and I'm not worried about it as the port can't be hit externally (firewall prohibits it) but just wanted to understand it. I also couldn't find anything in the rsyslog docs that talked about it.

Thanks!

This is just observed behavior I am curious about.

1 Answers

This isn't something that rsyslog is doing, but rather your OS.

Clients are assigned port numbers (random and sequential) by your operating system, as part of the sequence of system calls, that create a network connection. For example TCP and UDP typically use an "ephemeral" port for the client-end of a client–server communication.

These port numbers are - as you said - called "ephemeral" because they are valid only for the life of the connection and have no special significance.

As to why ephemeral ports are used.. I don't know. Maybe someone on ServerFault or Network Engineering can answer this question.

From my understanding ephemeral ports can be used either temporary or private. So if a service (temporarily) needs a port it can use an ephemeral port. After the service has done it's requests and has timed-out for some time, the port is released and can be used by some other service. This way a service doesn't block a port even though it doesn't even use it, or just frequently uses it.

Related