Network port detail · UDP/TCP

213

IPX
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Obsolete. RFC 1234 itself flags that tunneling exposes IPX to IP-internet risks: unauthorized IPX clients (password attacks), rogue IPX gateways diverting traffic, and on-path monitoring/manipulation — because IPX is not normally suspicious of its media.
// analyst note
An open 213 usually means a forgotten NetWare-era host or a DOSBox IPX game tunnel; legacy and low threat, but confirm it isn't an unexpected bridge into an internal IPX segment.
[ 01 ] — Context

About port 213/tcp.

Updated  ·  Confidence: High

Port 213/tcp is registered with IANA as ipx with the description "IPX," assignee Don Provan, and a blank reference field (dual-registered on TCP and UDP). It is the port assigned for tunneling Novell IPX datagrams over IP, defined in RFC 1234 (D. Provan, Novell, June 1991), which records that the Internet Assigned Numbers Authority assigned port 213 to the IPX encapsulation technique described in that memo. IPX (Internetwork Packet Exchange) is the connectionless network-layer protocol of Novell NetWare's IPX/SPX suite, functionally a derivative of the XNS IDP protocol; the encapsulation technique was developed independently by Schneider & Koch and by Novell, and Novell's IPTUNNEL — as well as DOSBox for retro multiplayer gaming — still defaults to UDP 213. The IANA reference field is blank. The protocol is largely obsolete, having faded as NetWare and IPX gave way to TCP/IP. Security-wise RFC 1234 itself flags that tunneling exposes IPX to IP-internet risks — unauthorized IPX clients mounting password attacks, rogue IPX gateways diverting traffic, and on-path monitoring or manipulation — because IPX is not normally suspicious of its media. For an analyst, an open 213 today usually means a forgotten NetWare-era host or a DOSBox IPX game tunnel; it is legacy and low threat, though worth confirming it is not an unexpected bridge into an internal IPX segment.

IANA assignment
ipx — "IPX"; reference (blank — no RFC cited in IANA registry); assignee Don Provan; dual-registered 213/tcp + 213/udp [IANA-assigned] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023)
Prevalence
low open-frequency (de-facto) [Well-established] — nmap-services file
Related ports
524 (Novell NCP); other NetWare-era services

Primary use

tunneling Novell IPX over IP (RFC 1234); obsolete

[Well-established] — RFC 1234

Other/unofficial uses

Novell IPTUNNEL; DOSBox IPX multiplayer gaming (UDP 213) [Well-established]

Security implications

obsolete; RFC 1234 notes tunneling exposes IPX to password attacks, rogue gateways, and on-path monitoring/manipulation [Well-established]

Typically seen on

NetWare-era hosts; DOSBox IPX tunnels

Analyst note
An open 213 usually means a forgotten NetWare-era host or a DOSBox IPX game tunnel; legacy and low threat, but confirm it isn't an unexpected bridge into an internal IPX segment.
[ 02 ] — Context

About port 213/udp.

Updated  ·  Confidence: Medium

Port 213/udp is registered with IANA as ipx, description "IPX," assignee Don Provan, with a blank Reference field and no registration or modification date recorded in the registry. It is dual-registered: 213/tcp carries the identical ipx/"IPX" entry, also attributed to Don Provan with no dates or reference. The underlying technique this assignment serves is described in RFC 1234, "Tunneling IPX Traffic through IP Networks" (D. Provan, Novell, Inc., June 1991), which specifies encapsulating Novell NetWare IPX (Internetwork Packet Exchange) datagrams inside UDP packets so IPX traffic can cross IP-only network segments — matching the port's assignee name and description. IANA's own Reference column for this row is blank, so RFC 1234 is background context rather than the registry's cited source, and is recorded here as such rather than backfilled into the reference field. RFC 1234 itself notes that tunneling IPX over an IP internet carries the general exposure risks of any IP-reachable service and that administrators bridging IPX networks onto IP should be aware of the added surface, but no CVE or modern vulnerability class specific to this port turned up. Secondary port-lookup aggregators (Connected, WhatPortIs, SpeedGuide, AuditMyPC) characterize the port as a legacy, rarely-seen assignment today, though none are primary sources and a SANS ISC per-port scanning page returned no populated statistics when checked, so current exposure/scan-volume figures are Unknown rather than assumed negligible or assumed active.

IANA assignment
ipx — "IPX"; Reference blank; assignee Don Provan; dual-registered 213/tcp + 213/udp, identical entry on both [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (local cache); IANA registry https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=213
Range class
well-known (0–1023) [Confirmed]
Registration/modification dates
blank in the IANA registry source; not fabricated [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
IANA Reference field
blank in the current registry row; RFC 1234 describes the encapsulation technique but is not the registry-listed Reference, so it is left blank rather than backfilled [Confirmed] — IANA registry (URL above)
Related ports
213/tcp — identical dual registration (ipx/"IPX", same assignee, no dates or reference) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry

Primary use

tunneling Novell NetWare IPX datagrams inside UDP so IPX traffic can traverse IP-only networks, per RFC 1234 (background — not IANA's cited Reference for this row)

[Confirmed] — https://www.rfc-editor.org/rfc/rfc1234.html, https://datatracker.ietf.org/doc/html/rfc1234

Other/unofficial uses

none confirmed beyond the historical IPX-tunneling role; no specific modern software confirmed to use this port

[Likely] — https://www.rfc-editor.org/rfc/rfc1234.html

Security implications

RFC 1234 (1991) notes general exposure risk from bridging IPX networks onto an IP internet; no CVE or modern vulnerability class specifically tied to this port was found in this pass

[Likely] — https://www.rfc-editor.org/rfc/rfc1234.html

Exposure/scanning notes

Unknown — SANS ISC's per-port activity page (isc.sans.edu/data/port/213) returned no populated statistics on fetch; secondary, non-primary aggregators describe the port as legacy/rarely seen but this is not independently confirmed [Unknown] — https://isc.sans.edu/data/port/213, https://www.connected.app/ports/213, https://whatportis.com/ports/213_internetwork-packet-exchange-ipx, https://www.speedguide.net/port.php?port=213, https://www.auditmypc.com/udp-port-213.asp

Typically seen on

historical Novell NetWare IPX-to-IP tunneling gateways; negligible expected exposure on modern networks

[Likely] — https://www.rfc-editor.org/rfc/rfc1234.html
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
ipx UDP 0.05%
ipx TCP 0.00%
IANA name
ipx
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.