Network port detail · UDP/TCP

102

Iso-tsap
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Classic S7comm has no authentication or encryption. Stuxnet (first uncovered June 2010) targeted Siemens SIMATIC S7-300/400 PLCs, injecting hidden code via STEP 7 (a PLC rootkit) and concealing it from operators; Symantec reported ~60% of infections in Iran and 200,000+ machines affected. Exposed S7 PLCs are found via Shodan and enumerated with PLCScan and the Nmap s7-info NSE script; S7 authentication has been shown bypassable/replayable (Beresford 2011; Rogue7 2019).
// analyst note
An open 102 is very likely a Siemens S7 PLC / industrial controller — a high-priority OT finding. Such devices should be air-gapped or tightly segmented; internet exposure is critical.
[ 01 ] — Context

About port 102/tcp.

Updated  ·  Confidence: High

Port 102/tcp is registered with IANA as iso-tsap with the description "ISO-TSAP Class 0," assignee Marshall Rose, and a blank reference field (dual-registered on TCP and UDP). The registered protocol is the ISO Transport Service on top of TCP, defined in RFC 1006 (May 1987, Marshall Rose and Dwight Cass), which carries the OSI connection-mode Transport Service (TSAP) Class 0 over TCP using a four-byte TPKT framing header plus COTP (ISO 8073 / RFC 905). The IANA reference field is blank. The dominant real-world relevance of port 102, however, is industrial: it is the port for Siemens S7 PLC communication (S7comm). The stack is Ethernet → IP → TCP → TPKT (RFC 1006) → COTP (ISO 8073) → S7comm, used by SIMATIC S7-300/400/1200/1500 programmable logic controllers and the associated engineering software (STEP 7, TIA Portal, WinCC) for programming, data read/write, and diagnostics, in use since the S7 line launched in 1994; newer S7-1200/1500 controllers use an encrypted variant, S7CommPlus. IEC 61850 MMS also uses port 102. This makes a clean separation essential — IANA registers the port as iso-tsap (RFC 1006), but the traffic in the field is overwhelmingly Siemens S7. The security story is a major one for operational technology: classic S7comm has no authentication or encryption, and Stuxnet — first uncovered in June 2010 — specifically targeted Siemens SIMATIC S7-300 and S7-400 PLCs, injecting hidden code via STEP 7 (a PLC rootkit) while concealing it from operators; Symantec reported in 2010 that around 60% of infected machines were in Iran, with the worm reaching well over 200,000 computers. Exposed S7 PLCs are routinely discovered via Shodan and enumerated with PLCScan and the Nmap s7-info NSE script, and exposure has been rising in recent OT-scanning studies. For an analyst, an open 102 is very likely a Siemens S7 PLC or industrial controller — a high-priority OT finding; such devices should be air-gapped or tightly segmented, and an internet-exposed 102 is a critical exposure.

IANA assignment
iso-tsap — "ISO-TSAP Class 0"; reference (blank — no RFC cited in IANA registry); assignee Marshall Rose; dual-registered 102/tcp + 102/udp [IANA-assigned] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023)
Prevalence
modest open-frequency in nmap-services; significant in ICS/OT scanning (de-facto) [Well-established] — nmap-services file, OT-exposure studies
Related ports (ICS cluster)
502 (Modbus), 20000 (DNP3), 44818 (EtherNet/IP), 47808 (BACnet)

De-facto use

Siemens S7 PLC communication (S7comm); IEC 61850 MMS (NOT separate IANA registrations)

[Well-established/Community] — ICS references

Primary use (registered)

ISO Transport Service over TCP, TSAP Class 0 (RFC 1006)

[Well-established] — RFC 1006

Other/unofficial uses

Siemens SIMATIC S7-300/400/1200/1500 PLC comms; STEP 7 / TIA Portal / WinCC; IEC 61850 MMS [Well-established]

Security implications

classic S7comm has no auth/encryption; Stuxnet (uncovered June 2010) targeted S7-300/400 PLCs (PLC rootkit via STEP 7; ~60% of infections in Iran; 200,000+ machines); exposed PLCs found via Shodan/PLCScan/nmap s7-info; S7 auth bypass/replay research (Beresford 2011, Rogue7 2019)

[Well-established/Threat-reported] — Stuxnet analyses, ICS-CERT/Siemens advisories

Typically seen on

Siemens S7 PLCs, industrial controllers, SCADA/OT networks

Analyst note
An open 102 is very likely a Siemens S7 PLC / industrial controller — a high-priority OT finding. Such devices should be air-gapped or tightly segmented; internet exposure is critical.
[ 02 ] — Context

About port 102/udp.

Updated  ·  Confidence: Medium

Port 102/udp is registered with IANA under the service name iso-tsap, described as "ISO-TSAP Class 0," with assignee and contact Marshall Rose and a blank reference field; the entry is dual-registered on TCP and UDP, where the UDP row is identical to the TCP row in service name and description. ISO-TSAP is the OSI-model Transport Service Access Point, and the practical reality of this port is that essentially all documented real-world traffic rides the TCP registration, not UDP. TCP port 102 carries Siemens S7 industrial communication (S7comm and S7comm-plus) between engineering stations and S7-300/400/1200/1500 PLCs via tools like SIMATIC Manager, TIA Portal, and WinCC, and it also carries ICCP (Inter-Control Center Communications Protocol) in power-grid SCADA. The protocol family is commonly associated in secondary sources with RFC 1006 ("ISO Transport Service on top of the TCP") and its predecessor RFC 983, but IANA's own Reference column is blank for both the TCP and UDP rows, so no RFC is recorded here rather than backfilling one. For an analyst, port 102 matters chiefly as an ICS/OT exposure point: S7comm over TCP 102 was the pathway Stuxnet used to reach Siemens S7-300/400 controllers, and the SANS Internet Storm Center tracks ongoing scanning against port 102. Crucially, no source found in this pass documents a specific, named application actively using 102/UDP in the wild — the UDP assignment exists in the registry, but its practical usage is Unknown, and the well-known S7comm/ICCP/Stuxnet-era activity is TCP-based.

IANA assignment
iso-tsap — "ISO-TSAP Class 0"; reference (blank — no RFC cited in IANA registry); assignee/contact Marshall Rose; dual-registered 102/tcp + 102/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry–272)
Range class
well-known (0–1023) [Confirmed]
IANA Reference
blank in IANA's own registry for both the TCP and UDP rows — recorded blank, not backfilled with RFC 1006/983 [Confirmed] — IANA registry
Registration/modification dates
blank in the source row — recorded null, not fabricated [Confirmed] — IANA registry

Primary use (registry)

ISO-TSAP Class 0 — OSI-model Transport Service Access Point

[Confirmed] — IANA registry

Security implications

TCP 102 is a well-documented ICS exposure point; S7comm over TCP 102 was the protocol Stuxnet used to reach Siemens S7-300/400 PLCs; SANS ISC tracks ongoing scanning of port 102. Whether UDP 102 sees comparable scanning is Unknown (sources describe TCP/ICS scanning without singling out UDP)

[Likely] — Wireshark S7comm wiki, SANS ISC port 102, Tenable NNM
Documented real-world use is TCP-centric
Siemens S7comm/S7comm-plus (S7-300/400/1200/1500 PLC programming, HMI/SCADA) and ICCP power-grid SCADA; no widely deployed UDP application on 102 was found [Likely] — Wireshark S7comm wiki, Siemens TIA docs
Commonly cited related RFCs (NOT the IANA Reference field)
RFC 1006 "ISO Transport Service on top of the TCP" and its predecessor RFC 983 — these document the TCP-based mechanism; the RFC-to-UDP linkage is Unknown [Likely] — IETF Datatracker RFC 1006, RFC 983
UDP-specific usage
Unknown — no source found naming a product or protocol actively using 102/UDP as distinct from the TCP registration [Unknown] — IANA registry
Analyst note
Treat the IANA UDP assignment as a registry fact; documented threat and application activity on port 102 is TCP-based (S7comm/ICCP). An anomalous 102/UDP responder is not explained by any known service found here and warrants investigation.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
iso-tsap UDP tsap ISO-TSAP Class 0 0.05%
iso-tsap TCP tsap ISO-TSAP Class 0 0.01%
IANA name
iso-tsap
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.