Network port detail · UDP/TCP

259

Esro-gen
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Rare/obscure with a minimal modern footprint. RFC 2188 carries an IESG Note warning of possible scalability issues (no IETF WG review). Secondary Check Point FW1-RDP overlap on UDP 259.
// analyst note
An open 259 most often means a niche ESRO/embedded deployment or a Check Point device; correlate with neighboring Check Point ports (256–258, 264).
[ 01 ] — Context

About port 259/tcp.

Updated  ·  Confidence: High

Port 259/tcp is registered with IANA as esro-gen with the description "Efficient Short Remote Operations," assignee Mohsen Banan, and a blank reference field (dual-registered on TCP and UDP). ESRO is defined in RFC 2188 ("AT&T/Neda's Efficient Short Remote Operations (ESRO) Protocol Specification Version 1.2," M. Banan, M. Taylor, and J. Cheng, Neda/AWS, September 1997, Informational). ESRO is a lightweight RPC/transaction protocol optimized for efficiency on constrained or wireless links — it was designed with CDPD in mind — offering reliable connectionless remote operations with minimal overhead, segmentation and reassembly, concatenation, and multiplexing, and supporting both two-way and three-way handshakes; early cited uses include short-message submission and delivery, credit-card authorization, and white-pages lookup. Notably RFC 2188 carries an IESG Note warning that it has not had the benefit of IETF Working Group review and has several issues that may be significant for scalability, and a reference implementation exists from Neda. The IANA reference field is blank. A secondary real-world association is worth flagging: on the same port number, 259/udp is widely labeled firewall1-rdp in nmap-services — Check Point FireWall-1's proprietary RDP protocol — so 259 has a weaker Check Point association alongside the much stronger one on 264. Security-wise the port is rare and obscure with a minimal modern footprint, the main caveats being the RFC's own scalability warning and the FW1-RDP overlap on UDP. For an analyst, an open 259 most often means either a niche ESRO/embedded deployment or a Check Point device, so it is worth correlating with neighboring Check Point ports (256–258, 264).

IANA assignment
esro-gen — "Efficient Short Remote Operations"; reference (blank — no RFC cited in IANA registry); assignee Mohsen Banan; dual-registered 259/tcp + 259/udp [IANA-assigned] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023)
Prevalence
nmap-services open-frequency ~0.000201 (de-facto) [Well-established] — nmap-services file
Related ports
ESRO/ESROS family; Check Point cluster 256–258, 264

Primary use

lightweight RPC/transaction protocol for short operations on constrained links (RFC 2188)

[Well-established] — RFC 2188

Other/unofficial uses

259/udp widely labeled firewall1-rdp (Check Point FW-1 proprietary RDP)

[Community/de-facto] — nmap-services

Security implications

rare/obscure; RFC 2188 IESG note warns of scalability issues; FW1-RDP overlap on UDP [Well-established]

Typically seen on

niche ESRO/embedded deployments; Check Point devices

Analyst note
An open 259 most often means a niche ESRO/embedded deployment or a Check Point device; correlate with neighboring Check Point ports (256–258, 264).
[ 02 ] — Context

About port 259/udp.

Updated  ·  Confidence: Medium

Port 259/udp is registered with IANA as esro-gen, described as "Efficient Short Remote Operations," with assignee and contact listed as Mohsen Banan. The Registration Date, Modification Date, and Reference/RFC columns are all blank in the IANA source registry, so no RFC is cited for this assignment and none should be inferred — the same service name, description, and assignee also appear on the adjacent row for 259/tcp, making this a genuine dual TCP/UDP registration rather than a coincidence. Separate from the IANA registration, several non-authoritative port-database sites document a historical, vendor-specific overload of this port: older Check Point FireWall-1/VPN-1 deployments reportedly used 259 for their RDP (Reliable Datagram Protocol) service during VPN session-key negotiation, cryptographic-algorithm selection, and integrity checking. This is a database/vendor artifact distinct from the IANA esro-gen assignment, not a change to it. SANS Internet Storm Center's live port-259 activity page shows ongoing generic internet background-radiation scanning against the port, with threat level marked "green" (low concern) at the time of this research pass; no CVE tied specifically to 259/udp was found. One aggregator explicitly notes no confirmed trojan/malware association despite the port appearing on a historical Check Point watchlist entry. No specific modern application or vendor product is reliably documented as actively using esro-gen today.

IANA assignment
esro-gen — "Efficient Short Remote Operations"; Reference/RFC column blank in the IANA registry; assignee/contact Mohsen Banan; dual-registered 259/tcp + 259/udp with identical name/description/assignee
[Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (row 581 for the tcp dual)
Range class
well-known (0–1023)
Prevalence
nmap-services observed open-frequency 259/udp ≈ 0.00084 — very low (roughly 8 in 10,000 scanned hosts in the nmap-services sample), about four times the paired 259/tcp figure of ≈ 0.000201. Notably, nmap-services labels the UDP row firewall1-rdp rather than esro-gen (the name it uses on the TCP row), independently corroborating the Check Point FireWall-1 RDP overload described above as the practical identity of the UDP side
[Confirmed] — nmap-services dataset
Related ports
259/tcp — identical dual IANA registration (same service name, description, assignee, contact) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry

Primary use

ESRO (Efficient Short Remote Operations), per IANA registration; no linked RFC/spec

[Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv

Other/unofficial uses

historical, non-IANA, vendor-specific overload — older Check Point FireWall-1/VPN-1 versions used port 259 for their RDP (Reliable Datagram Protocol) service in VPN session setup (key negotiation, DES/FWZ-1 algorithm selection, MD5 integrity checks)

[Likely] — https://www.auditmypc.com/udp-port-259.asp, https://isc.sans.edu/data/port/259

Security implications

SANS ISC's port-259 activity page showed ongoing generic mass internet-scanning traffic against the port (dozens of connection attempts per top source, observed 2026-07-17), threat level "green" (low concern) at fetch time; no CVE found tied specifically to 259/udp as of this pass [Likely — live/rolling snapshot, not a fixed historical fact] — https://isc.sans.edu/data/port/259

Malware/trojan association

none confirmed; auditmypc.com lists the port under a historical "Firewall-1 RDP" watchlist entry but states explicitly "Virus / Trojan: No"

[Likely] — https://www.auditmypc.com/udp-port-259.asp

Typically seen on

legacy/older Check Point FireWall-1 VPN-1 deployments (RDP overload, historical, non-IANA); otherwise generic scan-target traffic across the internet [Likely]

Analyst note
keep the IANA esro-gen registration and the separate vendor-specific Check Point RDP overload clearly distinct; treat SANS ISC scan-count figures as a dynamic snapshot at fetch time, not a static historical fact, and do not backfill an artificial "first seen" date.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
firewall1-rdp UDP Firewall 1 proprietary RDP protocol http://www.inside-security.de/fw1_rdp_poc.html 0.08%
esro-gen TCP efficient short remote operations 0.02%
IANA name
esro-gen
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.