Port 27017 — MongoDB
TCP registered
What runs on port 27017
The default MongoDB port.
Security considerations
Older versions bound to all interfaces with no authentication, which led to mass ransoming of exposed databases. Enable auth and bind privately.
Checking whether something is listening
# Linux / macOS — what is bound to the port
sudo lsof -i :27017
sudo ss -lntp | grep :27017
# Windows
netstat -ano | findstr :27017
Get-NetTCPConnection -LocalPort 27017
# is it reachable from outside?
nc -zv example.com 27017
curl -v telnet://example.com:27017
Freeing the port
# find the process, then stop it
sudo lsof -ti :27017 | xargs kill # Linux / macOS
netstat -ano | findstr :27017 # note the PID, then:
taskkill /PID <pid> /F # Windows
Should this port be open to the internet?
No. Port 27017 should never be reachable from a public address. Bind it to localhost or a private network, and reach it through a VPN or bastion host if remote access is genuinely needed. Internet-wide scanners find newly exposed instances of this service within minutes.
Quick reference
| Port | 27017 |
| Protocol | TCP |
| Service | MongoDB |
| Range | Registered (1024–49151) — any user process may bind |
Frequently asked questions
What is port 27017 used for?
The default MongoDB port.
Is it safe to open port 27017?
Older versions bound to all interfaces with no authentication, which led to mass ransoming of exposed databases. Enable auth and bind privately.
How do I check if port 27017 is open?
Locally, sudo lsof -i :27017 on macOS or Linux, or netstat -ano | findstr :27017 on Windows. From outside, nc -zv host 27017 tells you whether anything answers.
Why do I get "address already in use" on port 27017?
Another process is bound to it — often a previous run of your own program that did not exit cleanly. Find it with lsof -ti :27017 and stop it, or configure your application to use a different port.
Can I change the port this service uses?
Almost always yes, in the service's configuration. Moving off a default port reduces automated scan noise, but it is obfuscation rather than security — a real attacker scans all 65,535.