56
Summary
- // if you see it open
- Protocol obsolete since the 1980s as TCP/IP supplanted XNS. Third-party databases label XNS 'insecure' in general terms but cite no CVEs, exploit history, or measured scan volume for this port. Internet-facing exposure expected to be negligible; a responsive port 56 is best treated as an anomaly.
- // analyst note
- An open port 56 is not a recognized modern service; treat a responsive listener as an anomaly. The RAP-on-56 label seen in some databases is incorrect — RAP is port 38.
About port 56/tcp.
Port 56/tcp is registered with IANA as xns-auth with the description "XNS Authentication," assignee and contact both listed as Susie Armstrong, and a blank reference field (dual-registered on TCP and UDP). XNS Authentication is a component of Xerox Network Systems (XNS), the protocol suite developed at Xerox PARC in the mid-to-late 1970s that influenced much of the networking that followed. The authentication service on port 56 handled identity verification for users and devices on XNS-based local networks using a challenge-response scheme rooted in the Needham-Schroeder protocol — the same academic foundation later adopted by Kerberos. XNS specifications were placed in the public domain in 1977, and the suite seeded several derivative stacks, including Novell NetWare's IPX/SPX, Banyan VINES, and 3Com's 3+Share, though those derivatives did not necessarily reuse port 56 directly. The IANA reference field is blank — no RFC is cited in the registry, and registration/modification dates are not populated. For an analyst the practical takeaway is that this is an obsolete protocol: XNS fell out of use as TCP/IP became ubiquitous, and the assignment persists mainly as a historical artifact. A common point of confusion is that some third-party port databases also associate port 56 with the "Route Access Protocol (RAP)," but that is a secondary or erroneous attribution — IANA assigns port 56 exclusively to xns-auth, and RAP (RFC 1476) is formally assigned to port 38, not 56. The nmap-services dataset does carry a measured open-frequency for this port — 56/tcp at approximately 0.000013, the dataset's lowest nonzero step — while no Shodan research or documented CVEs specific to live port 56/tcp exposure were found, so any responsive port 56 today is best treated as an anomaly worth investigating rather than a recognized modern service.
- IANA assignment
xns-auth— "XNS Authentication"; reference (blank — no RFC cited in IANA registry); assignee/contact Susie Armstrong; dual-registered 56/tcp + 56/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry, lines 120–121)- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services observed open-frequency 56/tcp ≈ 0.000013 — the dataset's lowest nonzero step [Confirmed] — nmap-services dataset; sibling 56/udp ≈ 0.001285, about a hundred times higher but still negligible in absolute terms. No Shodan-derived exposure count specific to 56/tcp was found [Unknown]
- Related ports
- 38/tcp (Route Access Protocol — the correct RAP assignment, contrast); other XNS-era assignments
Primary use
identity verification within Xerox Network Systems (XNS) LANs; challenge-response based on the Needham-Schroeder protocol; both TCP and UDP assigned
Other/unofficial uses
some third-party databases (WhatPortIs) also list port 56 as "Route Access Protocol (RAP)," but RAP is formally port 38 per RFC 1476 — this appears to be a secondary/erroneous attribution
Common software
Xerox proprietary network equipment/software (late 1970s–1980s, e.g. DocuTech publishing systems); derivative stacks (NetWare IPX/SPX, Banyan VINES, 3+Share) inherited XNS architecture but not necessarily port 56; no modern implementer known
Security implications
protocol obsolete since the 1980s; third-party databases label XNS "insecure" in general terms but cite no CVEs, exploit history, or measured scan volume for this port; internet-facing exposure expected to be negligible
Typically seen on
legacy/obsolete Xerox-lineage systems; otherwise an anomaly worth investigating
- Analyst note
- An open port 56 is not a recognized modern service; treat a responsive listener as an anomaly. The RAP-on-56 label seen in some databases is incorrect — RAP is port 38.
About port 56/udp.
Port 56/udp is registered with IANA as xns-auth with the description "XNS Authentication," assignee and contact both listed as Susie Armstrong, and a blank reference field — the identical assignment also covers 56/tcp, so the port is dual-registered on TCP and UDP under one service name. XNS Authentication is a component of Xerox Network Systems (XNS), the protocol suite developed at Xerox PARC in the mid-to-late 1970s that influenced much of the networking that followed. The authentication service handled identity verification for users and devices on XNS-based local networks using a challenge-response scheme, so that credentials could be checked without transmitting passwords in the clear; the same Needham-Schroeder academic foundation later underpinned MIT's Kerberos. Notably, the XNS suite ran over its own transport, the Sequenced Packet Protocol (SPP), not TCP/IP — so the IANA TCP and UDP assignment for port 56 is a historical artifact of the early port registry rather than evidence of an IP-native service. The IANA reference field is blank: no RFC is cited in the registry, and registration and modification dates are not populated. For an analyst the practical takeaway is that this is an obsolete protocol — XNS fell out of use as TCP/IP became ubiquitous, and the assignment persists mainly as a legacy record. A recurring point of confusion is that some third-party port databases instead label port 56 as "Route Access Protocol (RAP)"; that is a secondary or erroneous attribution — IANA assigns port 56 exclusively to xns-auth, and RAP (RFC 1476) is formally assigned to port 38, not 56. No Shodan datasets or documented CVEs specific to live 56/udp exposure were found, and the one scan-derived measurement available — an nmap-services open-frequency of ≈ 0.001285, roughly 1 in 1,000 sampled hosts — is low enough to be background, so any responsive port 56 today is best treated as an anomaly worth investigating rather than a recognized modern service.
- IANA assignment
xns-auth— "XNS Authentication"; reference (blank — no RFC cited in IANA registry); assignee/contact Susie Armstrong; dual-registered 56/tcp + 56/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry)- Range class
- well-known (0–1023) [Confirmed]
- Registration / modification date
- blank in IANA registry — none published [Confirmed] — IANA registry (Reference and date columns blank)
- Prevalence
- nmap-services observed open-frequency 56/udp ≈ 0.001285 — very low (roughly 1 in 1,000 sampled hosts), 294th of 5,615 UDP entries; the TCP sibling 56/tcp is ≈ 0.000013, about 100× lower. Because UDP scans report open|filtered when nothing answers, a figure this size is consistent with silent hosts rather than live XNS Authentication services[Likely] — nmap-services dataset. No Shodan exposure data specific to 56/udp was found [Unknown]
- Related ports
- 38/tcp (Route Access Protocol — the correct RAP assignment, contrast); 56/tcp (same IANA xns-auth assignment); other XNS-era assignments
Primary use
identity verification within Xerox Network Systems (XNS) LANs via a challenge-response scheme (no passwords on the wire); XNS ran over its own SPP transport, not TCP/IP, so the TCP+UDP port-56 assignment is a registry artifact
Other/unofficial uses
some third-party databases (e.g. WhatPortIs) list port 56 as "Route Access Protocol (RAP)," but RAP is formally port 38 per RFC 1476 — this appears to be a secondary/erroneous attribution
Common software
Xerox proprietary network equipment/software (late 1970s–1980s); derivative stacks such as Novell NetWare (IPX/SPX), Banyan VINES, and AppleTalk inherited XNS architecture but did not reuse port 56 on TCP/IP; no modern implementer known to listen on 56/udp
Security implications
protocol obsolete since the 1980s; one third-party port database notes port 56 was historically flagged in virus/trojan listings but classifies the standard xns-auth assignment as non-malicious — no CVEs or named active exploit for this port were found; internet-facing exposure expected to be negligible, consistent with the very low nmap-services open-frequency
Typically seen on
legacy/obsolete Xerox-lineage systems; otherwise an anomaly worth investigating
- Lineage note
- XNS Authentication's challenge-response design traces to the Needham-Schroeder symmetric-key protocol and is the same lineage later used by Kerberos; XNS itself dates to the late 1970s [Likely] — https://www.connected.app/ckb/ports/56
- Analyst note
- An open port 56 is not a recognized modern service; treat a responsive listener as an anomaly. The RAP-on-56 label seen in some databases is incorrect — RAP is port 38. Because UDP is connectionless, scanners typically report 56/udp as open|filtered when nothing answers.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| xns-auth | UDP | XNS Authentication | 0.13% |
| xns-auth | TCP | XNS Authentication | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.