Description
The default port is 6379 for Redis and 11211 for Memcached. Using a default port is not itself a vulnerability, and changing it cannot prevent service discovery or unauthorized access. Actual risk depends on reachable networks and the authentication and transport protection supported by the engine.
Potential impact
- Broad access can let clients that do not need the service attempt connections.
- Treating a port change as access control can leave necessary security groups or authentication settings unconfigured.
Remediation
- Use subnets and security groups to allow only approved applications, and configure authentication and transport encryption supported by the engine.
- If organizational policy or operational needs require another port, set
cache_portand update application, firewall and monitoring settings together. Keeping the default port requires the same access controls.
Examples
These historical Memcached excerpts compare only the port. For new deployments, use currently supported engine versions and node types, with an actual subnet group and Availability Zone.
Before
- name: ElastiCache 생성
community.aws.elasticache:
name: test-please-delete
state: present
engine: memcached
cache_engine_version: 1.4.14
node_type: cache.m1.small
num_nodes: 1
cache_port: 11211
cache_subnet_group: default
zone: us-east-1d
This uses Memcached’s default port, 11211. That value alone does not establish external exposure or unauthorized access.
After
- name: ElastiCache 생성
community.aws.elasticache:
name: test-please-delete
state: present
engine: memcached
cache_engine_version: 1.4.14
node_type: cache.m1.small
num_nodes: 1
cache_port: 11212
cache_subnet_group: default
zone: us-east-1d
This changes the port to 11212. It does not strengthen permissions or network boundaries, so check those controls separately.