195
Summary
- // if you see it open
- No modern/mainstream software found implementing this service; the registration reads as functionally retired. No sourced measurement of current internet exposure/scan prevalence was found for 195/tcp — presumed negligible given its age and DoD-specific origin, but not confirmed by data, so reported as Unknown. An unexpected open 195/tcp on a contemporary host would be anomalous and worth investigating.
About port 195/tcp.
Port 195/tcp is registered with IANA under the service name dn6-nlm-aud, described as "DNSIX Network Level Module Audit," with no assignee, contact, registration date, modification date, or RFC reference recorded in the registry — it is dual-registered on both TCP and UDP with identical entries on both transports. DNSIX stands for "DoD Network Security for Information Exchange," a legacy U.S. Department of Defense protocol suite from the 1980s-90s designed to embed security and classification labels, and audit attributes, into network traffic on early DoD "trusted network" infrastructure. Within that suite, port 195 serves as the Network Level Module audit channel, sitting alongside two sibling registrations: 90/tcp+udp (dnsix, the base session-management service) and 196/tcp+udp (dn6-smm-red, the Session Management Module Audit Redirector). Cisco IOS still documents legacy dnsix-* configuration commands, such as dnsix-dmdp for the DNSIX Message Delivery Protocol audit-trail transport, in its Security Command Reference — evidence that some enterprise router platforms historically carried support for the DNSIX family, though not specifically for port 195. No modern, mainstream open-source or commercial daemon was found that actively implements or listens on 195/tcp today; the registration reads as functionally retired. No dataset quantifying real-world scan prevalence or exposure for 195/tcp was located, so that figure is reported honestly as unknown rather than estimated.
- IANA assignment
dn6-nlm-aud— "DNSIX Network Level Module Audit"; no assignee, contact, or reference recorded; dual-registered 195/tcp + 195/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-477; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml- IANA reference field
- blank — no RFC is cited for this entry in the registry; left blank per no-fabrication policy [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml
- Range class
- well-known (0–1023) [Confirmed]
- Registration/modification dates
- not recorded in the IANA registry for this entry [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
- Prevalence/exposure data
- no sourced scan or exposure measurement found for 195/tcp; reported as Unknown rather than estimated [Unknown]
Primary use
DNSIX suite Network Level Module audit channel, part of a legacy DoD security-labeling/audit protocol family [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml; https://www.cisco.com/en/US/docs/ios/security/command/reference/sec_d2.pdf
Security implications
an unexpected open 195/tcp on a modern host would be anomalous given the protocol's retired, DoD-specific origin; no known malware associations found
- Related registrations
- 90/tcp+udp (
dnsix, base session management) and 196/tcp+udp (dn6-smm-red, Session Management Module Audit Redirector) [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml - Current software support
- no known mainstream/modern daemon implements dn6-nlm-aud; functionally retired [Likely] — general web search, no contradicting source found
About port 195/udp.
Port 195/udp is registered with IANA under the service name dn6-nlm-aud, described as "DNSIX Network Level Module Audit." The registry row carries no assignee, contact, registration date, modification date, reference/RFC, service code, or assignment notes — all of those columns are blank in the source CSV, and that blankness is reported honestly rather than filled with an invented RFC or date. The entry is dual-registered: 195/tcp carries an identical service name and description immediately preceding the udp row in the registry. The port sits in a small cluster of adjacent DNSIX-related registrations spanning 195–199: 196/dn6-smm-red (DNSIX Session Management Module Audit Redirector), 197/dls (Directory Location Service), and 198/dls-mon (Directory Location Service Monitor). DNSIX (Defense Network Security Information Exchange) was a U.S. Department of Defense-era network security data-labeling and audit architecture from the 1980s–90s, built for trusted/multi-level-secure networking rather than as a general-purpose application protocol. No source found documents any currently deployed mainstream software, OS component, or product that actively implements dn6-nlm-aud today, so the port should be treated as a dormant legacy reservation rather than an in-use service. No confirmed malware or trojan association was found for this port. General UDP-scanning literature notes that UDP services as a class tend to be scanned/audited less thoroughly than TCP. The nmap-services dataset does carry a port-specific figure: an observed open-frequency of ≈ 0.000395 for 195/udp — very low, roughly 4 in 10,000 scanned hosts — against 0 for the paired 195/tcp row. Beyond that figure no honeypot or Shodan/Censys statistics specific to this port were located, so broader exposure claims are left Unknown rather than asserted.
- IANA assignment
dn6-nlm-aud— "DNSIX Network Level Module Audit"; reference field blank (no RFC cited); assignee/contact blank; dual-registered 195/tcp + 195/udp (identical row) [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=5- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services observed open-frequency 195/udp ≈ 0.000395 — very low (roughly 4 in 10,000 scanned hosts in the nmap-services sample); the paired 195/tcp row carries a frequency of 0 (never observed open in the same sample)[Confirmed] — nmap-services dataset. No honeypot or Shodan/Censys exposure count for this port was located [Unknown]
- Related ports
- 196/udp (dn6-smm-red), 197 (dls), 198 (dls-mon) — same DNSIX-era registration cluster, immediately adjacent in the IANA registry [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=5
Primary use
DNSIX Network Level Module Audit — part of the U.S. DoD-era DNSIX (Defense Network Security Information Exchange) trusted-networking labeling/audit framework, not a general application protocol [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=5 , https://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers
Other/unofficial uses
none found; no verifiable current mainstream software actively listens on or implements this port [Unknown]
Security implications
no confirmed malware/trojan association — AuditMyPC lists "Virus / Trojan: No" and GRC's Port Authority page lists no security risks for port 195
Typically seen on
no current hosts confirmed; historically would apply to DNSIX-aware DoD trusted-networking systems, otherwise dormant [Unknown]
- Analyst note
- traffic observed on 195/udp today is more plausibly generic internet background-scan noise than legitimate DNSIX activity; the nmap-services open-frequency for the port is very low (≈ 0.000395), and beyond it only general (non-port-specific) UDP-scan commentary exists, so treat broader scanning-exposure claims as Unknown[Likely/Unknown] — nmap-services dataset; https://nmap.org/book/scan-methods-udp-scan.html
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| dn6-nlm-aud | UDP | DNSIX Network Level Module Audit | 0.04% |
| dn6-nlm-aud | TCP | DNSIX Network Level Module Audit | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.