Port 2376: Docker TLS

Port 2376 is the Docker Engine API secured with TLS client certificates, the safer counterpart to the unencrypted API on port 2375. It is the port Docker's own documentation recommends when the API needs to be reachable remotely.

TCPInfrastructure & orchestration Encrypted
Port number2376
ServiceDocker daemon API (TLS)
ProtocolTCP
CategoryInfrastructure & orchestration
Default encryptionYes (TLS/SSH)

How do I check whether port 2376 is open?

Port 2376 carries TCP, so a connection either completes its handshake or it does not, which makes the check definitive.

QuestionCommandWhat to know
Is it open on a remote host?nc -vz example.com 2376A TCP handshake either completes or it does not, so netcat gives a definitive answer in one line.
Same check on WindowsTest-NetConnection example.com -Port 2376Built into PowerShell. TcpTestSucceeded in the output is the answer; telnet is not installed by default on modern Windows.
What is listening locally?ss -tlnp | grep ':2376 'Lists the process bound to port 2376 on Linux. On macOS use lsof -nP -iTCP:2376 -sTCP:LISTEN, on Windows netstat -ano | findstr :2376

Replace example.com with the host you are testing. A blocked port and a port with nothing listening on it look identical from the outside, so if a service should be running, check locally before blaming the firewall.

Frequently asked questions

What is port 2376 used for?

Port 2376 is the Docker Engine API secured with TLS client certificates, the safer counterpart to the unencrypted API on port 2375. It is the port Docker's own documentation recommends when the API needs to be reachable remotely.

Is port 2376 TCP or UDP?

Port 2376 (Docker TLS) uses TCP.

Is port 2376 secure?

Yes. Port 2376 carries encrypted traffic by default, so data in transit is protected.

Should I open port 2376 on my firewall?

Only if you specifically need Docker TLS. Expose it to the smallest set of trusted sources, and never open database or Windows-service ports to the whole internet.