221
Summary
- // if you see it open
- One secondary, self-disclaimed port-warning database reports no known trojan/virus association for TCP 221; not corroborated against a primary threat-intel source. Do not confuse with port 222 (rsh-spx), a separate IANA registration.
- // analyst note
- an open port 221 today is unexpected given IPX/SPX's obsolescence; verify it is not a misidentification of port 222 (
rsh-spx) before treating it as a live legacy service.
About port 221/tcp.
Port 221/tcp is registered with IANA as fln-spx, described as "Berkeley rlogind with SPX auth," with the assignee, contact, registration/modification dates, and reference columns all blank in the registry (the IANA registry search view corroborates the same name and description). The entry is dual-registered: UDP 221 carries the identical service name and description, not the superficially similar rsh-spx, which is a separate IANA registration on port 222/tcp and 222/udp — an initial raw-text registry read conflated the two, but the IANA xhtml search view and independent secondary port databases both confirm UDP 221 matches TCP 221 as fln-spx. Functionally, the name describes a variant of Berkeley's rlogind (the remote-login daemon behind the historical rlogin/rsh "r-commands") that authenticated over Novell's IPX/SPX protocol stack rather than standard TCP/IP-based rlogin trust. IPX/SPX was the dominant Novell NetWare networking stack from the late 1980s through the mid-1990s and was progressively removed from mainstream operating systems afterward — Linux dropped native SPX support in 2002 and IPX support entirely by 2018 — so no actively maintained software implementing SPX-authenticated rlogin on this port was identified. No RFC or reference document is cited by IANA for this assignment, so that field is reported blank rather than invented. Shodan's documentation lists port 221 among the ports it actively scans across the internet, though no scan-prevalence statistics were retrieved in this pass, and a single secondary, self-disclaimed port-warning database reports no known trojan/virus association for TCP 221 without independent corroboration against a primary threat-intel source.
- IANA assignment
fln-spx— "Berkeley rlogind with SPX auth"; reference blank; assignee/contact blank; dual-registered 221/tcp + 221/udp, identical name/description on both [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-545; IANA registry search view- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- not measured in this pass (no scan-prevalence statistics retrieved); Shodan documentation lists 221 among the ports it actively scans [Likely] — book.shodan.io/behind-the-scenes/ports/
- Related ports
- 222/tcp,udp (
rsh-spx— separate IANA registration, easily confused with this entry)
Primary use
legacy Berkeley rlogind (remote-login daemon) variant authenticated via Novell IPX/SPX rather than standard TCP/IP rlogin auth
Other/unofficial uses
none identified in this pass; IPX/SPX (Novell NetWare stack) was phased out of mainstream OSes by the early 2000s–2018 (e.g. Linux dropped SPX in 2002, IPX in 2018), and no actively maintained software implementing SPX-authenticated rlogin on this port was found — a general-search negative result, not an exhaustive audit
Security implications
one secondary, self-disclaimed port-warning database reports no known trojan/virus association for TCP 221; not independently corroborated against a primary threat-intel source
Typically seen on
no current legitimate deployments identified; historically, Unix hosts bridging into Novell NetWare/IPX-SPX environments
- Do-not-confuse
rsh-spxis a separate IANA registration on 222/tcp+udp, not 221 — an initial raw-text registry read conflated these; corrected against the IANA xhtml search view and a secondary port database [Confirmed] — IANA registry search view; t1shopper.com port 222- Analyst note
- an open port 221 today is unexpected given IPX/SPX's obsolescence; verify it is not a misidentification of port 222 (
rsh-spx) before treating it as a live legacy service.
About port 221/udp.
Port 221/udp is registered with IANA under the service name fln-spx, described tersely as "Berkeley rlogind with SPX auth." The entry is dual-registered — 221/tcp carries the identical service name and description — and every other IANA registry column (assignee, contact, registration date, modification date, reference) is blank for both transports, confirmed directly from the live IANA CSV. The name points to a legacy variant of Berkeley's rlogind (the remote-login daemon underlying the classic Unix r-services family, alongside rsh and rexec) that authenticated over SPX — Novell's Sequenced Packet Exchange, the connection-oriented transport in the IPX/SPX stack — rather than the plain TCP/IP trust-based authentication used by standard rlogin on port 513. That combination places fln-spx squarely in the 1990s interoperability layer between Novell NetWare networks and Unix/BSD hosts. No modern or actively maintained software implementing 221/udp turned up in this research pass; the handful of port-lookup aggregators that reference it only echo the IANA string, suggesting the registration is effectively dormant. auditmypc.com explicitly rates the port clean of any known virus or trojan association, and it does not appear on Gary Kessler's well-known bad-ports list. As a member of the r-services family by lineage, though, it inherits that family's general reputation for weak, trust-based authentication as a protocol class — a class-level caveat, not a port-221-specific finding, since no live deployments were found to evaluate directly.
- IANA assignment
fln-spx— "Berkeley rlogind with SPX auth"; assignee, contact, registration date, modification date, and reference all blank; dual-registered 221/tcp + 221/udp with identical service name/description [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (lines 544–545); https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv- Range class
- well-known (0–1023) [Confirmed]
- IANA RFC/reference field
- blank in the registry — no RFC is cited by IANA for this entry; a third-party aggregator's "RFC 1282" association was checked and excluded as non-authoritative, not recorded [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv
Primary use
legacy Berkeley rlogind variant authenticating via SPX (Novell IPX/SPX), likely a 1990s-era interop mechanism between NetWare and Unix/BSD r-services environments
Security implications
no confirmed trojan/malware association (auditmypc.com explicitly reports "Virus/Trojan: No" for UDP 221); not present on Gary Kessler's bad-ports list; general r-services-class weak/trust-based-auth caveat applies at the protocol-family level, not as a port-221-specific finding
- Current/live usage
- no modern software found actively implementing or listening on 221/udp; aggregator listings only mirror the IANA string with no deployment examples — appears dormant/legacy [Likely] — http://www.t1shopper.com/tools/port-number/221/; https://www.adminsub.net/tcp-udp-port-finder/221
- Live internet-wide exposure/listener counts (e.g. Shodan/Censys)
- not queried in this research pass [Unknown]
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| fln-spx | UDP | Berkeley rlogind with SPX auth | 0.06% |
| fln-spx | TCP | Berkeley rlogind with SPX auth | 0.01% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.