271
Summary
- // if you see it open
- No CVE associated with the port specifically. As an NEA/NAC posture-assessment transport, a misconfigured or unauthenticated PT-TLS endpoint could in principle leak host posture/compliance details or allow spoofed posture reports, but no documented exploit or vulnerability was found in this research pass.
About port 271/tcp.
Port 271/tcp is registered with IANA as pt-tls, described as the "IETF Network Endpoint Assessment (NEA) Posture Transport Protocol over TLS," assignee [IESG], contact [IETF_Chair], with a registration date of 2012-07-31 and reference RFC 6876. RFC 6876 was published in February 2013 and defines PT-TLS, a transport protocol that carries NEA posture-assessment message exchanges — the back-and-forth by which a network access control (NAC) server evaluates an endpoint's security compliance (patch level, running software, configuration state) — inside a mutually- or server-authenticated TLS tunnel. It sits in the broader NEA architecture alongside sibling transports like PT-EAP, letting posture checks happen either at network admission or afterward, independent of the underlying network access method. The UDP side of port 271 is registered as Reserved with no service name, description, assignee, or reference populated, i.e. no UDP service is defined here — this is a TCP-only assignment. Real-world footprint is modest: the open-source strongSwan IPsec/VPN suite ships a documented PT-TLS client package, but broader vendor adoption of PT-TLS servers is not well documented in public sources. Passive-scanning telemetry (SANS ISC) shows only sparse, low-single-digit daily hits on the port, consistent with generic internet background noise rather than a targeted campaign, and no CVE is associated with the port specifically.
- IANA assignment (TCP)
pt-tls— "IETF Network Endpoint Assessment (NEA) Posture Transport Protocol over TLS (PT-TLS)"; assignee [IESG]; contact [IETF_Chair]; registration date 2012-07-31; reference RFC 6876 [Confirmed] — two independent angles agree (cached IANA CSV registry rows 605-606, and the live IANA service-names-port-numbers XML) — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml- IANA assignment (UDP)
- Reserved — no service name, description, assignee, contact, or reference populated in the registry [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (rows 605-606)
- Range class
- well-known (0–1023)
- Related ports
- other NEA-family transports (PT-EAP, defined separately in the NEA architecture, no fixed registered port); the broader NAC/posture-assessment protocol space
Primary use
PT-TLS transports NEA posture-assessment message exchanges inside a TLS-protected tunnel, used in NAC workflows to evaluate an endpoint's compliance (patch level, configuration, status) at or after network admission
Exposure / scanning
sparse, low single-digit daily scan hits observed on SANS ISC's port page as of the 2026-07-17 check, consistent with generic background-noise sweeps rather than a targeted campaign; no CVE listed against the port [Likely, single source, light research pass] — https://isc.sans.edu/port.html?port=271
Malware associations
none identified in this research pass
- RFC / publication
- RFC 6876, published February 2013 [Confirmed] — https://datatracker.ietf.org/doc/html/rfc6876
- Known implementations
- strongSwan (open-source IPsec/VPN suite) ships a documented PT-TLS client package; broader server-side/vendor adoption prevalence is unverified [Likely] — https://launchpad.net/ubuntu/trusty/+package/strongswan-pt-tls-client
About port 271/udp.
Port 271/udp carries the status Reserved in the IANA Service Name and Transport Protocol Port Number Registry: the Service Name, Description, Assignee, Contact, Registration Date, Modification Date, Reference, Service Code, and Assignment Notes columns are all blank on this row — no protocol, organization, or RFC is tied to the UDP side of port 271. This stands in contrast to its TCP sibling: 271/tcp is actively registered as pt-tls, the IETF Network Endpoint Assessment (NEA) Posture Transport Protocol over TLS, assignee [IESG], contact [IETF_Chair], registered 2012-07-31, defined in RFC 6876. That assignment does not extend to UDP — the two rows are independent, and 271/udp being reserved simply means the number is held aside (reserved status typically signals IANA does not consider it available for a new independent assignment) rather than assigned to any active or historical service. No RFC, no known implementation, and no documented malware or exploit history attach to the UDP entry specifically. Passive-scanning telemetry for port 271 overall (SANS ISC) shows only sparse, low-single-digit daily hits, consistent with generic internet background noise rather than a targeted campaign, but that telemetry does not cleanly separate TCP from UDP traffic, so it cannot be attributed to the UDP side with confidence. For an analyst, 271/udp should be treated as inert: a responsive host on this UDP port is not explained by any registered service and would warrant investigation as unusual rather than expected.
- IANA assignment (UDP)
- Reserved — Service Name, Description, Assignee, Contact, Registration Date, Modification Date, Reference, Service Code, and Assignment Notes all blank in the registry [Confirmed] — two independent angles agree (cached registry CSV and live IANA XML/TXT registry) — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml
- Range class
- well-known (0–1023) [Confirmed]
- IANA Reference field
- blank — no RFC number populated for the UDP row; left blank per no-fabrication policy, not invented [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (row 606)
- Related ports
- 271/tcp (pt-tls, RFC 6876, the active sibling assignment); the broader NEA/NAC posture-assessment protocol space, which has no fixed UDP transport
Primary use
none — no service is defined or assigned on 271/udp
Other/unofficial uses
none documented
Exposure / scanning
SANS ISC's port-271 page shows only sparse, low-single-digit daily scan hits overall as of the 2026-07-17 check, consistent with generic background-noise sweeps; the page does not separate TCP from UDP telemetry, so this cannot be confidently attributed to the UDP side
Malware associations
none identified in this research pass
- TCP/UDP relationship
- 271/tcp is separately, actively registered as
pt-tls(IETF NEA Posture Transport Protocol over TLS), assignee [IESG], contact [IETF_Chair], registered 2012-07-31, RFC 6876 — this is a TCP-only assignment and does not extend to 271/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (rows 605-606); https://datatracker.ietf.org/doc/html/rfc6876 - Analyst note
- 271/udp is reserved dead space with no assigned service — a responsive host on this port is unexplained by any registered protocol and should be treated as anomalous, not routine.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| pt-tls | TCP | IETF Network Endpoint Assessment (NEA) Posture Transport Protocol over TLS (PT-TLS) | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.