259
Summary
- // if you see it open
- Rare/obscure with a minimal modern footprint. RFC 2188 carries an IESG Note warning of possible scalability issues (no IETF WG review). Secondary Check Point FW1-RDP overlap on UDP 259.
- // analyst note
- An open 259 most often means a niche ESRO/embedded deployment or a Check Point device; correlate with neighboring Check Point ports (256–258, 264).
About port 259/tcp.
Port 259/tcp is registered with IANA as esro-gen with the description "Efficient Short Remote Operations," assignee Mohsen Banan, and a blank reference field (dual-registered on TCP and UDP). ESRO is defined in RFC 2188 ("AT&T/Neda's Efficient Short Remote Operations (ESRO) Protocol Specification Version 1.2," M. Banan, M. Taylor, and J. Cheng, Neda/AWS, September 1997, Informational). ESRO is a lightweight RPC/transaction protocol optimized for efficiency on constrained or wireless links — it was designed with CDPD in mind — offering reliable connectionless remote operations with minimal overhead, segmentation and reassembly, concatenation, and multiplexing, and supporting both two-way and three-way handshakes; early cited uses include short-message submission and delivery, credit-card authorization, and white-pages lookup. Notably RFC 2188 carries an IESG Note warning that it has not had the benefit of IETF Working Group review and has several issues that may be significant for scalability, and a reference implementation exists from Neda. The IANA reference field is blank. A secondary real-world association is worth flagging: on the same port number, 259/udp is widely labeled firewall1-rdp in nmap-services — Check Point FireWall-1's proprietary RDP protocol — so 259 has a weaker Check Point association alongside the much stronger one on 264. Security-wise the port is rare and obscure with a minimal modern footprint, the main caveats being the RFC's own scalability warning and the FW1-RDP overlap on UDP. For an analyst, an open 259 most often means either a niche ESRO/embedded deployment or a Check Point device, so it is worth correlating with neighboring Check Point ports (256–258, 264).
- IANA assignment
esro-gen— "Efficient Short Remote Operations"; reference (blank — no RFC cited in IANA registry); assignee Mohsen Banan; dual-registered 259/tcp + 259/udp [IANA-assigned] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023)
- Prevalence
- nmap-services open-frequency ~0.000201 (de-facto) [Well-established] — nmap-services file
- Related ports
- ESRO/ESROS family; Check Point cluster 256–258, 264
Primary use
lightweight RPC/transaction protocol for short operations on constrained links (RFC 2188)
Other/unofficial uses
259/udp widely labeled firewall1-rdp (Check Point FW-1 proprietary RDP)
Security implications
rare/obscure; RFC 2188 IESG note warns of scalability issues; FW1-RDP overlap on UDP [Well-established]
Typically seen on
niche ESRO/embedded deployments; Check Point devices
- Analyst note
- An open 259 most often means a niche ESRO/embedded deployment or a Check Point device; correlate with neighboring Check Point ports (256–258, 264).
About port 259/udp.
Port 259/udp is registered with IANA as esro-gen, described as "Efficient Short Remote Operations," with assignee and contact listed as Mohsen Banan. The Registration Date, Modification Date, and Reference/RFC columns are all blank in the IANA source registry, so no RFC is cited for this assignment and none should be inferred — the same service name, description, and assignee also appear on the adjacent row for 259/tcp, making this a genuine dual TCP/UDP registration rather than a coincidence. Separate from the IANA registration, several non-authoritative port-database sites document a historical, vendor-specific overload of this port: older Check Point FireWall-1/VPN-1 deployments reportedly used 259 for their RDP (Reliable Datagram Protocol) service during VPN session-key negotiation, cryptographic-algorithm selection, and integrity checking. This is a database/vendor artifact distinct from the IANA esro-gen assignment, not a change to it. SANS Internet Storm Center's live port-259 activity page shows ongoing generic internet background-radiation scanning against the port, with threat level marked "green" (low concern) at the time of this research pass; no CVE tied specifically to 259/udp was found. One aggregator explicitly notes no confirmed trojan/malware association despite the port appearing on a historical Check Point watchlist entry. No specific modern application or vendor product is reliably documented as actively using esro-gen today.
- IANA assignment
esro-gen— "Efficient Short Remote Operations"; Reference/RFC column blank in the IANA registry; assignee/contact Mohsen Banan; dual-registered 259/tcp + 259/udp with identical name/description/assignee[Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (row 581 for the tcp dual)- Range class
- well-known (0–1023)
- Prevalence
- nmap-services observed open-frequency 259/udp ≈ 0.00084 — very low (roughly 8 in 10,000 scanned hosts in the nmap-services sample), about four times the paired 259/tcp figure of ≈ 0.000201. Notably, nmap-services labels the UDP row
firewall1-rdprather thanesro-gen(the name it uses on the TCP row), independently corroborating the Check Point FireWall-1 RDP overload described above as the practical identity of the UDP side[Confirmed] — nmap-services dataset - Related ports
- 259/tcp — identical dual IANA registration (same service name, description, assignee, contact) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Primary use
ESRO (Efficient Short Remote Operations), per IANA registration; no linked RFC/spec
Other/unofficial uses
historical, non-IANA, vendor-specific overload — older Check Point FireWall-1/VPN-1 versions used port 259 for their RDP (Reliable Datagram Protocol) service in VPN session setup (key negotiation, DES/FWZ-1 algorithm selection, MD5 integrity checks)
Security implications
SANS ISC's port-259 activity page showed ongoing generic mass internet-scanning traffic against the port (dozens of connection attempts per top source, observed 2026-07-17), threat level "green" (low concern) at fetch time; no CVE found tied specifically to 259/udp as of this pass [Likely — live/rolling snapshot, not a fixed historical fact] — https://isc.sans.edu/data/port/259
Malware/trojan association
none confirmed; auditmypc.com lists the port under a historical "Firewall-1 RDP" watchlist entry but states explicitly "Virus / Trojan: No"
Typically seen on
legacy/older Check Point FireWall-1 VPN-1 deployments (RDP overload, historical, non-IANA); otherwise generic scan-target traffic across the internet [Likely]
- Analyst note
- keep the IANA
esro-genregistration and the separate vendor-specific Check Point RDP overload clearly distinct; treat SANS ISC scan-count figures as a dynamic snapshot at fetch time, not a static historical fact, and do not backfill an artificial "first seen" date.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| firewall1-rdp | UDP | Firewall 1 proprietary RDP protocol http://www.inside-security.de/fw1_rdp_poc.html | 0.08% |
| esro-gen | TCP | efficient short remote operations | 0.02% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.