213
Summary
- // if you see it open
- Obsolete. RFC 1234 itself flags that tunneling exposes IPX to IP-internet risks: unauthorized IPX clients (password attacks), rogue IPX gateways diverting traffic, and on-path monitoring/manipulation — because IPX is not normally suspicious of its media.
- // analyst note
- An open 213 usually means a forgotten NetWare-era host or a DOSBox IPX game tunnel; legacy and low threat, but confirm it isn't an unexpected bridge into an internal IPX segment.
About port 213/tcp.
Port 213/tcp is registered with IANA as ipx with the description "IPX," assignee Don Provan, and a blank reference field (dual-registered on TCP and UDP). It is the port assigned for tunneling Novell IPX datagrams over IP, defined in RFC 1234 (D. Provan, Novell, June 1991), which records that the Internet Assigned Numbers Authority assigned port 213 to the IPX encapsulation technique described in that memo. IPX (Internetwork Packet Exchange) is the connectionless network-layer protocol of Novell NetWare's IPX/SPX suite, functionally a derivative of the XNS IDP protocol; the encapsulation technique was developed independently by Schneider & Koch and by Novell, and Novell's IPTUNNEL — as well as DOSBox for retro multiplayer gaming — still defaults to UDP 213. The IANA reference field is blank. The protocol is largely obsolete, having faded as NetWare and IPX gave way to TCP/IP. Security-wise RFC 1234 itself flags that tunneling exposes IPX to IP-internet risks — unauthorized IPX clients mounting password attacks, rogue IPX gateways diverting traffic, and on-path monitoring or manipulation — because IPX is not normally suspicious of its media. For an analyst, an open 213 today usually means a forgotten NetWare-era host or a DOSBox IPX game tunnel; it is legacy and low threat, though worth confirming it is not an unexpected bridge into an internal IPX segment.
- IANA assignment
ipx— "IPX"; reference (blank — no RFC cited in IANA registry); assignee Don Provan; dual-registered 213/tcp + 213/udp [IANA-assigned] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023)
- Prevalence
- low open-frequency (de-facto) [Well-established] — nmap-services file
- Related ports
- 524 (Novell NCP); other NetWare-era services
Primary use
tunneling Novell IPX over IP (RFC 1234); obsolete
Other/unofficial uses
Novell IPTUNNEL; DOSBox IPX multiplayer gaming (UDP 213) [Well-established]
Security implications
obsolete; RFC 1234 notes tunneling exposes IPX to password attacks, rogue gateways, and on-path monitoring/manipulation [Well-established]
Typically seen on
NetWare-era hosts; DOSBox IPX tunnels
- Analyst note
- An open 213 usually means a forgotten NetWare-era host or a DOSBox IPX game tunnel; legacy and low threat, but confirm it isn't an unexpected bridge into an internal IPX segment.
About port 213/udp.
Port 213/udp is registered with IANA as ipx, description "IPX," assignee Don Provan, with a blank Reference field and no registration or modification date recorded in the registry. It is dual-registered: 213/tcp carries the identical ipx/"IPX" entry, also attributed to Don Provan with no dates or reference. The underlying technique this assignment serves is described in RFC 1234, "Tunneling IPX Traffic through IP Networks" (D. Provan, Novell, Inc., June 1991), which specifies encapsulating Novell NetWare IPX (Internetwork Packet Exchange) datagrams inside UDP packets so IPX traffic can cross IP-only network segments — matching the port's assignee name and description. IANA's own Reference column for this row is blank, so RFC 1234 is background context rather than the registry's cited source, and is recorded here as such rather than backfilled into the reference field. RFC 1234 itself notes that tunneling IPX over an IP internet carries the general exposure risks of any IP-reachable service and that administrators bridging IPX networks onto IP should be aware of the added surface, but no CVE or modern vulnerability class specific to this port turned up. Secondary port-lookup aggregators (Connected, WhatPortIs, SpeedGuide, AuditMyPC) characterize the port as a legacy, rarely-seen assignment today, though none are primary sources and a SANS ISC per-port scanning page returned no populated statistics when checked, so current exposure/scan-volume figures are Unknown rather than assumed negligible or assumed active.
- IANA assignment
ipx— "IPX"; Reference blank; assignee Don Provan; dual-registered 213/tcp + 213/udp, identical entry on both [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (local cache); IANA registry https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=213- Range class
- well-known (0–1023) [Confirmed]
- Registration/modification dates
- blank in the IANA registry source; not fabricated [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
- IANA Reference field
- blank in the current registry row; RFC 1234 describes the encapsulation technique but is not the registry-listed Reference, so it is left blank rather than backfilled [Confirmed] — IANA registry (URL above)
- Related ports
- 213/tcp — identical dual registration (
ipx/"IPX", same assignee, no dates or reference) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Primary use
tunneling Novell NetWare IPX datagrams inside UDP so IPX traffic can traverse IP-only networks, per RFC 1234 (background — not IANA's cited Reference for this row)
Other/unofficial uses
none confirmed beyond the historical IPX-tunneling role; no specific modern software confirmed to use this port
Security implications
RFC 1234 (1991) notes general exposure risk from bridging IPX networks onto an IP internet; no CVE or modern vulnerability class specifically tied to this port was found in this pass
Exposure/scanning notes
Unknown — SANS ISC's per-port activity page (isc.sans.edu/data/port/213) returned no populated statistics on fetch; secondary, non-primary aggregators describe the port as legacy/rarely seen but this is not independently confirmed [Unknown] — https://isc.sans.edu/data/port/213, https://www.connected.app/ports/213, https://whatportis.com/ports/213_internetwork-packet-exchange-ipx, https://www.speedguide.net/port.php?port=213, https://www.auditmypc.com/udp-port-213.asp
Typically seen on
historical Novell NetWare IPX-to-IP tunneling gateways; negligible expected exposure on modern networks
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| ipx | UDP | — | 0.05% |
| ipx | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.