131
Summary
- // if you see it open
- Unknown — no CVEs, advisories, or malware associations specific to port 131 were found in this pass.
- // analyst note
- Port 131 has almost no independently verifiable documentation beyond its bare IANA label; treat unexpected traffic as Cisco-device-specific and investigate rather than assume a known general-purpose service.
About port 131/tcp.
Port 131 is registered with IANA under the service name cisco-tna, described simply as "cisco TNATIVE," and the registration is dual: both the TCP and UDP rows in the IANA Service Name and Transport Protocol Port Number Registry carry the identical name and description. Beyond that bare label, the registry entry is unusually thin — the Assignee, Contact, Registration Date, Modification Date, and Reference columns are all blank for this row, which itself is a data point: no RFC or IANA reference document was ever cited, and the site's convention is to leave that field blank rather than invent one. A web search for independent documentation of "TNATIVE" as a protocol turned up nothing beyond mirrors of the same IANA registry line (t1shopper, auditmypc, SpeedGuide, adminsub.net, GRC all simply republish "cisco-tna / cisco TNATIVE" without elaboration); no Cisco product manual, IETF draft, or RFC describing the wire protocol's mechanics could be located. That absence is itself informative: this reads as a legacy Cisco registration from the era when vendors reserved numbers for internal or native terminal/console-style services without ever publishing a public spec, similar in spirit to other sparsely documented Cisco-registered ports in this same range. Given the lack of any named daemon, software package, or exposure/scanning statistics tied to this port, an analyst encountering traffic on 131/tcp or 131/udp should treat it as an unusual, likely Cisco-device-specific signal rather than a well-understood general-purpose service, and should not assume behavior beyond what the bare registry name implies.
- IANA assignment
cisco-tna— "cisco TNATIVE"; dual-registered 131/tcp + 131/udp with identical name/description [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (lines 339–340); cross-checked against https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml- IANA reference/RFC
- blank in the registry — no RFC or reference document cited; left blank rather than invented [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
- Range class
- registered (0–1023 is well-known technically, but this entry carries no first-party assignee/date metadata beyond the bare name)
- Prevalence / exposure scanning notes
- Unknown — no dated Shodan/Censys/honeypot statistics specific to port 131 were found; reasoned as low-prevalence given its obscurity, but this is inference, not a sourced statistic [Unknown]
- Related ports
- other sparsely documented Cisco-registered service-name entries in the IANA registry's well-known range
Protocol mechanics
Unknown — no Cisco documentation, RFC, or IETF draft describing "TNATIVE" in detail was found in this pass; treated as an unverified legacy registration rather than guessed at
Common software/daemons
Unknown — no vendor manual or independent technical writeup identifies specific software binding to this port [Unknown]
Typically seen on
Cisco networking equipment, inferred from the vendor-specific registration name; not independently confirmed by a product manual [Likely]
- Assignee / contact / registration date / modification date
- Unknown — all blank in the registry source [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
- Analyst note
- Port 131 has almost no independently verifiable documentation beyond its bare IANA label; treat unexpected traffic as Cisco-device-specific and investigate rather than assume a known general-purpose service.
About port 131/udp.
Port 131/udp is registered with IANA under the service name cisco-tna, described simply as "cisco TNATIVE." The registry entry is dual-registered: the identical service name and description also appear for 131/tcp, so the assignment covers both transports rather than being UDP-specific. Beyond the bare registry label, there is little independently documented technical detail about what TNATIVE actually does. No RFC or IANA reference number is cited for this port, no assignee or contact metadata is listed, and no registration or modification date appears in the registry data, so those fields are reported as blank rather than guessed. A pass of general web sources (the IANA registry pages themselves, Wikipedia's port list, and several third-party port-lookup sites such as SpeedGuide, GRC's Port Authority, and auditmypc.com) turned up no Cisco product documentation, RFC, or vendor whitepaper that names or explains "TNATIVE" beyond echoing the same IANA label — these sites function as registry mirrors rather than independent sources. One of those third-party sites carries a generic, boilerplate-style warning that the port "has been used by a Trojan or virus in the past," a claim that recurs verbatim across many unrelated ports on that same site and is not corroborated by any dated, named-malware report, CVE, or vendor advisory found elsewhere. There is no evidence of active internet-wide scanning campaigns or known exploitation targeting 131/udp as of this research pass. In short: a legitimate but obscure and sparsely documented Cisco-registered assignment, with no confirmed security history beyond an uncorroborated legacy claim.
- IANA assignment
cisco-tna— "cisco TNATIVE"; reference (blank — no RFC cited in IANA registry); assignee/contact not listed [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (row 340, udp) and IANA Service Name and Transport Protocol Port Number Registry, https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt- Dual registration
- identical service name and description also registered for 131/tcp (row 339 of the same registry) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
- Range class
- well-known (0–1023)
- Registration/modification dates
- not present in the IANA registry data; left blank rather than invented [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
- Related ports
- 131/tcp (identical dual registration)
Primary use
registered to Cisco under the label "TNATIVE"; no independent technical documentation of the protocol's function could be found beyond the registry label itself
Common software
Unknown — no currently-shipping Cisco IOS/IOS-XE feature or third-party daemon could be confirmed as actively using this port [Unknown]
Security implications
no documented CVE, vendor advisory, or recent scanning/honeypot report specific to 131/udp; one third-party site (auditmypc.com) carries a generic, unverified "used by a Trojan or virus in the past" warning that appears as boilerplate across many unrelated ports on that site, so it is noted but not treated as a substantiated finding
Typically seen on
legacy/low-traffic; no evidence of routine exposure in current internet-wide scans
- Analyst note
- Sparsely documented Cisco assignment; treat an observed 131/udp listener as a Cisco-related legacy service rather than a common consumer or server protocol, and do not assume malicious intent from the port number alone absent other evidence.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| cisco-tna | UDP | cisco TNATIVE | 0.06% |
| cisco-tna | TCP | cisco TNATIVE | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.