172
Summary
- // if you see it open
- No CVEs or documented security incidents are tied to port 172 or the cl-1 service. Gary Kessler's bad-ports reference does not list it. AuditMyPC (lower-authority aggregator) explicitly marks TCP 172 'Virus/Trojan: No', in contrast to the adjacent port 171 which that same source flags.
- // analyst note
- essentially dormant legacy reservation; a responsive port 172 in the wild would be unusual and worth flagging as an anomaly rather than treated as expected traffic.
About port 172/tcp.
Port 172 is dually registered with IANA on both TCP and UDP under the service name cl-1, described as "Network Innovations CL/1," with assignee and contact both listed as [Kevin_DeVault] (IANA Service Name and Transport Protocol Port Number Registry; local cached copy the IANA Service Name and Transport Protocol Port Number Registry, lines 421-430). A second registry row, cl/1, is an explicitly historic alias for the same port and description: IANA's own registry notes read "IANA assigned this well-formed service name as a replacement for 'cl/1'" for the current name, and "This entry is now historic, not usable for use with many common service discovery mechanisms" for the alias. No RFC or IANA reference is cited for either row, and no registration or modification date is recorded — consistent with many sparse legacy well-known-port registrations in this range, such as the neighboring port 171. No protocol specification, vendor documentation, or product page describing "Network Innovations" or the CL/1 protocol's wire behavior could be located, so beyond the bare name-to-number reservation the protocol is effectively undocumented publicly and no current software is known to bind to it. Empirically the port is nearly dormant: nmap's real-world scan corpus records an open-frequency of 0.000000 for 172/tcp and 0.000494 for 172/udp. No CVEs or documented security incidents are tied to port 172 or the cl-1 service; Gary Kessler's widely used bad-ports reference does not list it at all, and the lower-authority AuditMyPC aggregator explicitly marks TCP port 172 "Virus / Trojan: No" (noted here only for contrast with the adjacent port 171 entry, which that same aggregator does flag). Net assessment: this is a legitimate but essentially unused legacy IANA reservation with no documented current use and no security history worth flagging.
- IANA assignment
cl-1(aliascl/1) — "Network Innovations CL/1"; reference blank; assignee/contact [Kevin_DeVault]; dual-registered 172/tcp + 172/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-430; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services open-frequency 172/tcp = 0.000000 (statistically unobserved in real-world scans); 172/udp = 0.000494 (very low, nonzero) [Confirmed] — https://svn.nmap.org/nmap/nmap-services
- Related ports
- 171/tcp+udp, an adjacent legacy Network Innovations-era registration under a different assignee (no direct successor/related protocol identified for CL/1) [Likely] — the IANA Service Name and Transport Protocol Port Number Registry-420
Primary use
bare IANA name-to-number reservation for a legacy vendor protocol ("Network Innovations CL/1"); no protocol specification or vendor documentation located
Other/unofficial uses
none identified; no current software found binding to this port under cl-1/cl/1 [Unknown]
Security implications
no CVEs or documented incidents tied to port 172 or cl-1; absent from Gary Kessler's bad-ports reference; AuditMyPC explicitly marks TCP 172 "Virus/Trojan: No" (contrast: the same low-authority aggregator flags the adjacent port 171)
Typically seen on
no confirmed deployments identified; a legacy, effectively dormant reservation [Unknown]
- Dates
- no registration or modification date published by IANA for this entry [Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml
- Analyst note
- essentially dormant legacy reservation; a responsive port 172 in the wild would be unusual and worth flagging as an anomaly rather than treated as expected traffic.
About port 172/udp.
Port 172/udp is registered with IANA under the service name cl-1, described simply as "Network Innovations CL/1," with assignee and contact both listed as Kevin DeVault. The registry row carries no RFC or reference number, no registration or modification date, and no service code — every metadata column beyond the description and assignee is blank in the canonical entry. The same service name cl-1 is dual-registered on 172/tcp with an identical description, assignee, and contact, and both the TCP and UDP rows for port 172 additionally carry a separate, older alias entry spelled cl/1 (slash form). That alias row is explicitly marked historic: its Assignment Notes state it is "an alias to cl-1" and "now historic, not usable for use with many common service discovery mechanisms," meaning cl-1 is the current well-formed name and cl/1 is a deprecated predecessor kept in the registry for reference. Beyond the bare IANA listing, no vendor documentation, protocol specification, or actively maintained software implementing CL/1 could be located — "Network Innovations" is not a well-documented vendor in current search results, and general port-reference mirror sites add no independent information. Empirical Nmap scan-frequency data shows the port is almost never observed open in the wild, and no malware or trojan association is confirmed for UDP 172 — no CVE, vendor advisory, or named threat-intelligence source ties a malware family to this port.
- IANA assignment
- service name
cl-1(well-formed name), description "Network Innovations CL/1," assignee/contact[Kevin_DeVault], reference field blank [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-427; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt - Range class
- well-known (0–1023) [Confirmed] — port number 172 falls within the IANA well-known range
- IANA reference/RFC
- none present for port 172 (tcp or udp); left blank rather than inferred [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
- Prevalence
- Nmap's nmap-services frequency data lists udp/172 at probability ≈0.000494 and tcp/172 at ≈0.000000 — essentially never observed open [Confirmed] — https://svn.nmap.org/nmap/nmap-services
Protocol technical details
no public specification, product page, or RFC could be located for CL/1; the vendor "Network Innovations" is not otherwise documented [Unknown]
Common software
no modern application or open-source project found that implements or listens on this port; general port-lookup sites only mirror the bare IANA entry [Unknown] — https://tcp-udp-ports.com/port-172.htm; https://www.speedguide.net/port.php?port=172; http://www.t1shopper.com/tools/port-number/172/
- Dual TCP/UDP registration
- 172/tcp is registered to the identical
cl-1service name, description, assignee, and contact [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-422 - Historic alias
- a separate
cl/1(slash-form) entry is registered on both 172/tcp and 172/udp, with Assignment Notes stating it is an alias tocl-1and now historic/not usable for common service discovery [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-430 - Security history
- no confirmed malware association — no CVE, vendor advisory, or named threat-intelligence record ties a malware family to UDP 172 [Unknown] — no primary source found
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| cl-1 | UDP | Network Innovations CL/1 | 0.05% |
| cl-1 | TCP | cl/1 | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.