321
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — No documented software, vendor use, or protocol specification implements port 321, so there is no legitimate reason for it to be open on any host and a live listener warrants investigation.
- // analyst note
- treat 321 as a bare, undocumented legacy IANA reservation; do not attribute a working protocol or common software to it without new sourcing.
- // if you see it open
- No documented software or protocol implements this port. A live listener on 321/tcp or 321/udp has no known legitimate explanation and should be treated as worth investigating (misconfiguration, custom/unofficial use, or possible backdoor). Do not cite RFC 1621 for this port — that RFC is an unrelated, never-deployed 1990s network-layer proposal that merely shares the name "Pip"; IANA lists no reference for port 321.
About port 321/tcp.
Port 321/tcp is IANA-registered under the service name pip with only the bare description "PIP" and no RFC or protocol specification behind it, so no legitimate deployed service is known to run on it — it should not be expected, and should not be allowed, on the public internet or on an internal network.
The registry entry lists assignee and contact as Gordon Mohr, with both the Registration Date and Modification Date fields blank in the cached IANA CSV, consistent with an old, pre-RFC 6335-era per-request reservation rather than a documented, specified protocol. Port 321/udp carries an identical, separately registered row (dual registration), but the content is the same bare "pip" label.
Some secondary port-lookup aggregators attach "RFC 1621" to this port, but RFC 1621 ("Pip Near-term Architecture," May 1994, Historic status) is an unrelated Bellcore next-generation-network-layer proposal that was merged into SIPP in 1993 and never deployed; IANA's own registry cites no reference for port 321, so this appears to be a name coincidence rather than a sourced link. No current or historical software, vendor documentation, or scan-telemetry source was found describing real-world traffic on port 321.
- IANA assignment
pip— description "PIP"; reference blank (no RFC cited); assignee/contact Gordon Mohr; dual-registered 321/tcp + 321/udp with identical row content [Confirmed] — IANA Service Names and Port Numbers Registry (cached CSV, lines 653-654)- Range class
- registered (321 falls in the 0–1023 well-known range, but functionally an obscure legacy reservation)
- Registration/modification dates
- blank in the IANA registry — not recorded, no date fabricated [Confirmed] — IANA Service Names and Port Numbers Registry
- Related ports
- none identified as a documented cluster
Primary use
Unknown — no documented protocol specification or deployed software found; the registration appears to be a bare, per-request legacy IANA assignment [Unknown]
Other/unofficial uses
an unrelated RFC 1621 ("Pip Near-term Architecture") is sometimes wrongly cited by secondary sites for this port; treat as a name coincidence, not a sourced link
Security implications
no known legitimate software uses this port; an open 321/tcp or 321/udp has no documented legitimate explanation and merits investigation [Unknown/Likely]
Typically seen on
Unknown — no vendor, scan, or malware documentation identified for this port
- Analyst note
- treat 321 as a bare, undocumented legacy IANA reservation; do not attribute a working protocol or common software to it without new sourcing.
About port 321/udp.
Port 321/udp is registered with IANA under the service name pip (dual-registered alongside 321/tcp) to assignee Gordon Mohr, but the registry carries no RFC reference and no registration or modification dates, and no confirmed contemporary software is known to use it — so its real-world purpose is Unknown, and it should not be assumed to belong on the public internet.
The name most likely traces to Pip, an early-1990s IPv6 candidate protocol ("the P Internet Protocol") documented in RFC 1621 (May 1994, status Historic) alongside competing IPng proposals SIP and CATNIP. Pip was merged into SIPP in 1993, whose ideas eventually shaped IPv6, but Pip itself was never adopted or deployed. IANA's own Reference field is blank, so this RFC linkage is inferred from matching era, contact, and naming rather than confirmed by the registry, and is reported here as Likely, not Confirmed.
No actively maintained software is known to use UDP/321 for the registered pip purpose today. Several generic port-lookup aggregator sites associate port 321 with IBM Tivoli Storage Manager's "Secure Remote Protocol," but no primary IBM documentation corroborates this, and these templated directories are known to recycle inaccurate content across unrelated ports, so the claim is flagged Unknown rather than reported as fact.
- IANA assignment
pip— "PIP"; dual-registered 321/tcp + 321/udp; assignee/contact[Gordon_Mohr]; reference field blank [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 654 (udp) / line 653 (tcp); IANA service-names-port-numbers registry- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- Unknown — no scan-frequency or nmap-services data was found for this port in this research pass [Unknown]
- Related ports
- 321/tcp (identical dual registration, service name, and assignee) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 653
Primary use
registered as pip; the name likely refers to the historic Pip IPng candidate protocol (RFC 1621, May 1994, status Historic), though IANA's own Reference field does not cite this — inferred from era/contact/naming, not stated by the registry
Other/unofficial uses
unverified aggregator claim of association with IBM Tivoli Storage Manager "Secure Remote Protocol"; no primary IBM source corroborates it [Unknown] — https://www.auditmypc.com/udp-port-321.asp, https://portsmaster.org/port-321/, https://www.speedguide.net/port.php?port=321
Security implications
no CVEs, malware families, or notable Shodan/mass-scan writeups tied to this port were found; any observed traffic is more likely misconfiguration or unrelated use than a legitimate pip service [Unknown]
Typically seen on
Unknown — no confirmed deployed software or host population identified [Unknown]
- Analyst note
- registry-only entry with no confirmed real-world software; treat any observed UDP/321 traffic as unexplained and worth investigating rather than assumed benign.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| pip | UDP | — | 0.06% |
| pip | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.