Network port detail · UDP/TCP

195

Dn6-nlm-aud
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No modern/mainstream software found implementing this service; the registration reads as functionally retired. No sourced measurement of current internet exposure/scan prevalence was found for 195/tcp — presumed negligible given its age and DoD-specific origin, but not confirmed by data, so reported as Unknown. An unexpected open 195/tcp on a contemporary host would be anomalous and worth investigating.
[ 01 ] — Context

About port 195/tcp.

Updated  ·  Confidence: Medium

Port 195/tcp is registered with IANA under the service name dn6-nlm-aud, described as "DNSIX Network Level Module Audit," with no assignee, contact, registration date, modification date, or RFC reference recorded in the registry — it is dual-registered on both TCP and UDP with identical entries on both transports. DNSIX stands for "DoD Network Security for Information Exchange," a legacy U.S. Department of Defense protocol suite from the 1980s-90s designed to embed security and classification labels, and audit attributes, into network traffic on early DoD "trusted network" infrastructure. Within that suite, port 195 serves as the Network Level Module audit channel, sitting alongside two sibling registrations: 90/tcp+udp (dnsix, the base session-management service) and 196/tcp+udp (dn6-smm-red, the Session Management Module Audit Redirector). Cisco IOS still documents legacy dnsix-* configuration commands, such as dnsix-dmdp for the DNSIX Message Delivery Protocol audit-trail transport, in its Security Command Reference — evidence that some enterprise router platforms historically carried support for the DNSIX family, though not specifically for port 195. No modern, mainstream open-source or commercial daemon was found that actively implements or listens on 195/tcp today; the registration reads as functionally retired. No dataset quantifying real-world scan prevalence or exposure for 195/tcp was located, so that figure is reported honestly as unknown rather than estimated.

IANA assignment
dn6-nlm-aud — "DNSIX Network Level Module Audit"; no assignee, contact, or reference recorded; dual-registered 195/tcp + 195/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-477; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml
IANA reference field
blank — no RFC is cited for this entry in the registry; left blank per no-fabrication policy [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml
Range class
well-known (0–1023) [Confirmed]
Registration/modification dates
not recorded in the IANA registry for this entry [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Prevalence/exposure data
no sourced scan or exposure measurement found for 195/tcp; reported as Unknown rather than estimated [Unknown]

Primary use

DNSIX suite Network Level Module audit channel, part of a legacy DoD security-labeling/audit protocol family [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml; https://www.cisco.com/en/US/docs/ios/security/command/reference/sec_d2.pdf

Security implications

an unexpected open 195/tcp on a modern host would be anomalous given the protocol's retired, DoD-specific origin; no known malware associations found

[Likely/Unknown] — no contradicting or supporting source found for malware association
Related registrations
90/tcp+udp (dnsix, base session management) and 196/tcp+udp (dn6-smm-red, Session Management Module Audit Redirector) [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml
Current software support
no known mainstream/modern daemon implements dn6-nlm-aud; functionally retired [Likely] — general web search, no contradicting source found
[ 02 ] — Context

About port 195/udp.

Updated  ·  Confidence: Medium

Port 195/udp is registered with IANA under the service name dn6-nlm-aud, described as "DNSIX Network Level Module Audit." The registry row carries no assignee, contact, registration date, modification date, reference/RFC, service code, or assignment notes — all of those columns are blank in the source CSV, and that blankness is reported honestly rather than filled with an invented RFC or date. The entry is dual-registered: 195/tcp carries an identical service name and description immediately preceding the udp row in the registry. The port sits in a small cluster of adjacent DNSIX-related registrations spanning 195–199: 196/dn6-smm-red (DNSIX Session Management Module Audit Redirector), 197/dls (Directory Location Service), and 198/dls-mon (Directory Location Service Monitor). DNSIX (Defense Network Security Information Exchange) was a U.S. Department of Defense-era network security data-labeling and audit architecture from the 1980s–90s, built for trusted/multi-level-secure networking rather than as a general-purpose application protocol. No source found documents any currently deployed mainstream software, OS component, or product that actively implements dn6-nlm-aud today, so the port should be treated as a dormant legacy reservation rather than an in-use service. No confirmed malware or trojan association was found for this port. General UDP-scanning literature notes that UDP services as a class tend to be scanned/audited less thoroughly than TCP. The nmap-services dataset does carry a port-specific figure: an observed open-frequency of ≈ 0.000395 for 195/udp — very low, roughly 4 in 10,000 scanned hosts — against 0 for the paired 195/tcp row. Beyond that figure no honeypot or Shodan/Censys statistics specific to this port were located, so broader exposure claims are left Unknown rather than asserted.

IANA assignment
dn6-nlm-aud — "DNSIX Network Level Module Audit"; reference field blank (no RFC cited); assignee/contact blank; dual-registered 195/tcp + 195/udp (identical row) [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=5
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services observed open-frequency 195/udp ≈ 0.000395 — very low (roughly 4 in 10,000 scanned hosts in the nmap-services sample); the paired 195/tcp row carries a frequency of 0 (never observed open in the same sample)
[Confirmed] — nmap-services dataset. No honeypot or Shodan/Censys exposure count for this port was located [Unknown]
Related ports
196/udp (dn6-smm-red), 197 (dls), 198 (dls-mon) — same DNSIX-era registration cluster, immediately adjacent in the IANA registry [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=5

Primary use

DNSIX Network Level Module Audit — part of the U.S. DoD-era DNSIX (Defense Network Security Information Exchange) trusted-networking labeling/audit framework, not a general application protocol [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=5 , https://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers

Other/unofficial uses

none found; no verifiable current mainstream software actively listens on or implements this port [Unknown]

Security implications

no confirmed malware/trojan association — AuditMyPC lists "Virus / Trojan: No" and GRC's Port Authority page lists no security risks for port 195

[Likely] — https://www.auditmypc.com/udp-port-195.asp , https://www.grc.com/port_195.htm

Typically seen on

no current hosts confirmed; historically would apply to DNSIX-aware DoD trusted-networking systems, otherwise dormant [Unknown]

Analyst note
traffic observed on 195/udp today is more plausibly generic internet background-scan noise than legitimate DNSIX activity; the nmap-services open-frequency for the port is very low (≈ 0.000395), and beyond it only general (non-port-specific) UDP-scan commentary exists, so treat broader scanning-exposure claims as Unknown
[Likely/Unknown] — nmap-services dataset; https://nmap.org/book/scan-methods-udp-scan.html
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
dn6-nlm-aud UDP DNSIX Network Level Module Audit 0.04%
dn6-nlm-aud TCP DNSIX Network Level Module Audit 0.00%
IANA name
dn6-nlm-aud
Transport
TCP (ALSO UDP — DUAL-REGISTERED, IDENTICAL ENTRY)
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.