Network port detail · TCP

271

Pt-tls
Protocol(s)
TCP
Range
System (0-1023)
Reference
RFC 6876

Summary

// if you see it open
No CVE associated with the port specifically. As an NEA/NAC posture-assessment transport, a misconfigured or unauthenticated PT-TLS endpoint could in principle leak host posture/compliance details or allow spoofed posture reports, but no documented exploit or vulnerability was found in this research pass.
[ 01 ] — Context

About port 271/tcp.

Updated  ·  Confidence: High

Port 271/tcp is registered with IANA as pt-tls, described as the "IETF Network Endpoint Assessment (NEA) Posture Transport Protocol over TLS," assignee [IESG], contact [IETF_Chair], with a registration date of 2012-07-31 and reference RFC 6876. RFC 6876 was published in February 2013 and defines PT-TLS, a transport protocol that carries NEA posture-assessment message exchanges — the back-and-forth by which a network access control (NAC) server evaluates an endpoint's security compliance (patch level, running software, configuration state) — inside a mutually- or server-authenticated TLS tunnel. It sits in the broader NEA architecture alongside sibling transports like PT-EAP, letting posture checks happen either at network admission or afterward, independent of the underlying network access method. The UDP side of port 271 is registered as Reserved with no service name, description, assignee, or reference populated, i.e. no UDP service is defined here — this is a TCP-only assignment. Real-world footprint is modest: the open-source strongSwan IPsec/VPN suite ships a documented PT-TLS client package, but broader vendor adoption of PT-TLS servers is not well documented in public sources. Passive-scanning telemetry (SANS ISC) shows only sparse, low-single-digit daily hits on the port, consistent with generic internet background noise rather than a targeted campaign, and no CVE is associated with the port specifically.

IANA assignment (TCP)
pt-tls — "IETF Network Endpoint Assessment (NEA) Posture Transport Protocol over TLS (PT-TLS)"; assignee [IESG]; contact [IETF_Chair]; registration date 2012-07-31; reference RFC 6876 [Confirmed] — two independent angles agree (cached IANA CSV registry rows 605-606, and the live IANA service-names-port-numbers XML) — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml
IANA assignment (UDP)
Reserved — no service name, description, assignee, contact, or reference populated in the registry [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (rows 605-606)
Range class
well-known (0–1023)
Related ports
other NEA-family transports (PT-EAP, defined separately in the NEA architecture, no fixed registered port); the broader NAC/posture-assessment protocol space

Primary use

PT-TLS transports NEA posture-assessment message exchanges inside a TLS-protected tunnel, used in NAC workflows to evaluate an endpoint's compliance (patch level, configuration, status) at or after network admission

[Confirmed] — https://datatracker.ietf.org/doc/html/rfc6876

Exposure / scanning

sparse, low single-digit daily scan hits observed on SANS ISC's port page as of the 2026-07-17 check, consistent with generic background-noise sweeps rather than a targeted campaign; no CVE listed against the port [Likely, single source, light research pass] — https://isc.sans.edu/port.html?port=271

Malware associations

none identified in this research pass

[Unknown] — not found, not confirmed absent
RFC / publication
RFC 6876, published February 2013 [Confirmed] — https://datatracker.ietf.org/doc/html/rfc6876
Known implementations
strongSwan (open-source IPsec/VPN suite) ships a documented PT-TLS client package; broader server-side/vendor adoption prevalence is unverified [Likely] — https://launchpad.net/ubuntu/trusty/+package/strongswan-pt-tls-client
[ 02 ] — Context

About port 271/udp.

Updated  ·  Confidence: Medium

Port 271/udp carries the status Reserved in the IANA Service Name and Transport Protocol Port Number Registry: the Service Name, Description, Assignee, Contact, Registration Date, Modification Date, Reference, Service Code, and Assignment Notes columns are all blank on this row — no protocol, organization, or RFC is tied to the UDP side of port 271. This stands in contrast to its TCP sibling: 271/tcp is actively registered as pt-tls, the IETF Network Endpoint Assessment (NEA) Posture Transport Protocol over TLS, assignee [IESG], contact [IETF_Chair], registered 2012-07-31, defined in RFC 6876. That assignment does not extend to UDP — the two rows are independent, and 271/udp being reserved simply means the number is held aside (reserved status typically signals IANA does not consider it available for a new independent assignment) rather than assigned to any active or historical service. No RFC, no known implementation, and no documented malware or exploit history attach to the UDP entry specifically. Passive-scanning telemetry for port 271 overall (SANS ISC) shows only sparse, low-single-digit daily hits, consistent with generic internet background noise rather than a targeted campaign, but that telemetry does not cleanly separate TCP from UDP traffic, so it cannot be attributed to the UDP side with confidence. For an analyst, 271/udp should be treated as inert: a responsive host on this UDP port is not explained by any registered service and would warrant investigation as unusual rather than expected.

IANA assignment (UDP)
Reserved — Service Name, Description, Assignee, Contact, Registration Date, Modification Date, Reference, Service Code, and Assignment Notes all blank in the registry [Confirmed] — two independent angles agree (cached registry CSV and live IANA XML/TXT registry) — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml
Range class
well-known (0–1023) [Confirmed]
IANA Reference field
blank — no RFC number populated for the UDP row; left blank per no-fabrication policy, not invented [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (row 606)
Related ports
271/tcp (pt-tls, RFC 6876, the active sibling assignment); the broader NEA/NAC posture-assessment protocol space, which has no fixed UDP transport

Primary use

none — no service is defined or assigned on 271/udp

[Confirmed] — IANA registry

Other/unofficial uses

none documented

[Unknown] — no source found describing any software or protocol using 271/udp

Exposure / scanning

SANS ISC's port-271 page shows only sparse, low-single-digit daily scan hits overall as of the 2026-07-17 check, consistent with generic background-noise sweeps; the page does not separate TCP from UDP telemetry, so this cannot be confidently attributed to the UDP side

[Likely, single ambiguous source] — https://isc.sans.edu/port.html?port=271

Malware associations

none identified in this research pass

[Unknown] — not found, not confirmed absent
TCP/UDP relationship
271/tcp is separately, actively registered as pt-tls (IETF NEA Posture Transport Protocol over TLS), assignee [IESG], contact [IETF_Chair], registered 2012-07-31, RFC 6876 — this is a TCP-only assignment and does not extend to 271/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (rows 605-606); https://datatracker.ietf.org/doc/html/rfc6876
Analyst note
271/udp is reserved dead space with no assigned service — a responsive host on this port is unexplained by any registered protocol and should be treated as anomalous, not routine.
// registry data

Service assignments.

1 entry
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
pt-tls TCP IETF Network Endpoint Assessment (NEA) Posture Transport Protocol over TLS (PT-TLS) 0.00%
IANA name
pt-tls
Transport
TCP
Range
System (0-1023)
Reference
RFC 6876

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.