Network port detail · UDP/TCP

130

Cisco-fna
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No documented CVEs or threat reporting specific to port 130 found. Given the lack of public protocol documentation, unexpected traffic on this port merits investigation rather than assumption of the unverified NAM association.
// analyst note
legacy Cisco proprietary registration with essentially no public documentation; treat any traffic on this port as worth investigating rather than assuming the community "NAM" association without corroboration.
[ 01 ] — Context

About port 130/tcp.

Updated  ·  Confidence: Medium

Port 130/tcp is registered with IANA as cisco-fna, described simply as "cisco FNATIVE." The registry entry is otherwise sparse: no assignee, no contact, no registration or modification date, and no RFC or other reference is listed — this is one of several legacy proprietary port registrations Cisco obtained directly from IANA in the pre-Internet-Draft era, when a company could reserve a small block of ports for internal router/switch services without publishing a specification. Port 130/udp carries the identical assignment (same service name, same description), which is typical of these older dual-registered entries rather than evidence of two distinct protocols. No public RFC, Internet-Draft, or Cisco technical document describing the FNATIVE wire protocol in detail was located; the name suggests a native/proprietary Cisco file- or resource-access mechanism from the same registration era as cisco-tna (131/tcp), but the actual function is not documented anywhere authoritative. A recurring but uncorroborated claim on Cisco community forums and several third-party port-lookup sites (t1shopper, GRC, auditmypc, and vendor signature docs such as Clavister's) associates port 130 with Cisco Catalyst 6000-series Network Analysis Module (NAM) traffic; this traces to informal forum discussion rather than to any IANA reference, RFC, or located primary Cisco source, so it is flagged here as unverified rather than stated as fact. The nmap-services dataset records an observed open-frequency of approximately 0.000013 for 130/tcp — the lowest nonzero step it carries — which puts measured exposure at the very bottom of the scale and matches what its age and narrow, proprietary purpose would predict; no Shodan/Censys-style exposure count specific to port 130 was found to corroborate it independently. No assignment date is fabricated for this entry: the IANA registry does not carry a per-line date for this legacy record, and none is invented here.

IANA assignment
cisco-fna — "cisco FNATIVE"; reference (blank — no RFC cited in IANA registry); assignee/contact blank [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt) and local registry cache (the IANA Service Name and Transport Protocol Port Number Registry, lines 337–338)
Range class
well-known (0–1023)
Dual registration
130/udp carries the identical service name and description as 130/tcp; both dual-registered with all other columns blank [Confirmed] — IANA registry (same source), local CSV lines 337–338
Registration/modification dates
not published by IANA for this entry; not fabricated [Confirmed absence] — IANA registry
Prevalence/exposure
nmap-services observed open-frequency 130/tcp ≈ 0.000013 — the dataset's lowest nonzero step [Confirmed] — nmap-services dataset; sibling 130/udp ≈ 0.000774, some sixty times higher. Rare, as its age and narrow proprietary purpose would predict; no Shodan/Censys-style exposure count found to corroborate independently [Unknown]
Related ports
cisco-tna on 131/tcp (adjacent Cisco proprietary registration from the same era)

Primary use

proprietary Cisco "FNATIVE" service; no public RFC or Cisco spec documents the wire protocol

[Unknown] — no authoritative source located describing function beyond the registry name/description

Other/unofficial uses

community forum claims link it to Cisco Catalyst 6000 NAM (Network Analysis Module) traffic; uncorroborated by any primary source

[Unknown, single-source/forum] — https://community.cisco.com/t5/other-network-architecture-subjects/cisco-port-fnative-cisco-fna-port-130/td-p/184260
Analyst note
legacy Cisco proprietary registration with essentially no public documentation; treat any traffic on this port as worth investigating rather than assuming the community "NAM" association without corroboration.
[ 02 ] — Context

About port 130/udp.

Updated  ·  Confidence: Medium

Port 130/udp is registered with IANA as cisco-fna, described simply as "cisco FNATIVE." The registry row carries no assignee, no contact, no registration or modification date, no reference/RFC, and no service code — every metadata column beyond the name and description is blank, which is itself informative: it marks this as an old-style registration predating IANA's stricter documentation requirements rather than a gap in this research pass. The identical row exists for 130/tcp with the same service name and description, confirming dual TCP/UDP registration under one name. Beyond the bare IANA listing, there is no official Cisco vendor documentation describing what FNATIVE actually does; the only elaboration available comes from secondary sources — a Cisco community forum thread and a legacy port-lookup aggregator — that associate the name with functionality on Cisco Catalyst 6000-series Network Analysis Module (NAM) hardware, an inference rather than a confirmed vendor specification. No mainstream open-source software, no CVE entries, and no named malware family were found tied specifically to this port. Several consumer-facing "port lookup" sites carry unsourced, undated claims that port 130 has historically been associated with Trojan/backdoor activity, but none names a specific malware family, cites a date, or points to a primary security advisory, so that claim is treated here as unverified folklore rather than an established threat. As a sub-1024 well-known port, 130/udp does fall within the range routinely swept by generic mass UDP scanners.

IANA assignment
cisco-fna — "cisco FNATIVE"; reference (blank — no RFC cited in IANA registry); assignee (blank); dual-registered 130/tcp + 130/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 338 (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt)
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services observed open-frequency 130/udp ≈ 0.000774 — very low (roughly 8 in 10,000 scanned hosts in the nmap-services sample); the paired 130/tcp row is far rarer at ≈ 0.000013, so essentially all observed activity on this port number sits on the UDP side [Confirmed] — nmap-services dataset
Related ports
130/tcp (identical dual registration)

Primary use

Cisco proprietary "FNATIVE" service; no official Cisco documentation of its function was located [Unknown]

Other/unofficial uses

community sourcing associates it with Cisco Catalyst 6000-series Network Analysis Module (NAM) functionality — a single, non-vendor source [Likely] — https://community.cisco.com/t5/other-network-architecture-subjects/cisco-port-fnative-cisco-fna-port-130/td-p/184260, http://www.t1shopper.com/tools/port-number/130/

Security implications

no CVE or named malware family found tied to this port; consumer port-lookup sites (auditmypc.com, SpeedGuide, Internet-Security.com) carry unsourced, undated Trojan/backdoor claims with no primary advisory — treated as unverified folklore, not a confirmed threat [Unknown] — https://www.auditmypc.com/udp-port-130.asp, https://www.speedguide.net/port.php?port=130, https://internet-security.com/ports/port-130-UDP.html

Typically seen on

legacy Cisco networking hardware/firmware (Catalyst 6000 NAM era, per community sourcing); otherwise anomalous [Likely]

Analyst note
A responsive 130/udp most plausibly reflects legacy Cisco equipment; the port carries no confirmed malware association and no official vendor specification of its function was found.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
cisco-fna UDP cisco FNATIVE 0.08%
cisco-fna TCP cisco FNATIVE 0.00%
IANA name
cisco-fna
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.