Network port detail · UDP/TCP

56

Xns-auth
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Protocol obsolete since the 1980s as TCP/IP supplanted XNS. Third-party databases label XNS 'insecure' in general terms but cite no CVEs, exploit history, or measured scan volume for this port. Internet-facing exposure expected to be negligible; a responsive port 56 is best treated as an anomaly.
// analyst note
An open port 56 is not a recognized modern service; treat a responsive listener as an anomaly. The RAP-on-56 label seen in some databases is incorrect — RAP is port 38.
[ 01 ] — Context

About port 56/tcp.

Updated  ·  Confidence: Medium

Port 56/tcp is registered with IANA as xns-auth with the description "XNS Authentication," assignee and contact both listed as Susie Armstrong, and a blank reference field (dual-registered on TCP and UDP). XNS Authentication is a component of Xerox Network Systems (XNS), the protocol suite developed at Xerox PARC in the mid-to-late 1970s that influenced much of the networking that followed. The authentication service on port 56 handled identity verification for users and devices on XNS-based local networks using a challenge-response scheme rooted in the Needham-Schroeder protocol — the same academic foundation later adopted by Kerberos. XNS specifications were placed in the public domain in 1977, and the suite seeded several derivative stacks, including Novell NetWare's IPX/SPX, Banyan VINES, and 3Com's 3+Share, though those derivatives did not necessarily reuse port 56 directly. The IANA reference field is blank — no RFC is cited in the registry, and registration/modification dates are not populated. For an analyst the practical takeaway is that this is an obsolete protocol: XNS fell out of use as TCP/IP became ubiquitous, and the assignment persists mainly as a historical artifact. A common point of confusion is that some third-party port databases also associate port 56 with the "Route Access Protocol (RAP)," but that is a secondary or erroneous attribution — IANA assigns port 56 exclusively to xns-auth, and RAP (RFC 1476) is formally assigned to port 38, not 56. The nmap-services dataset does carry a measured open-frequency for this port — 56/tcp at approximately 0.000013, the dataset's lowest nonzero step — while no Shodan research or documented CVEs specific to live port 56/tcp exposure were found, so any responsive port 56 today is best treated as an anomaly worth investigating rather than a recognized modern service.

IANA assignment
xns-auth — "XNS Authentication"; reference (blank — no RFC cited in IANA registry); assignee/contact Susie Armstrong; dual-registered 56/tcp + 56/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry, lines 120–121)
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services observed open-frequency 56/tcp ≈ 0.000013 — the dataset's lowest nonzero step [Confirmed] — nmap-services dataset; sibling 56/udp ≈ 0.001285, about a hundred times higher but still negligible in absolute terms. No Shodan-derived exposure count specific to 56/tcp was found [Unknown]
Related ports
38/tcp (Route Access Protocol — the correct RAP assignment, contrast); other XNS-era assignments

Primary use

identity verification within Xerox Network Systems (XNS) LANs; challenge-response based on the Needham-Schroeder protocol; both TCP and UDP assigned

[Likely] — https://en.wikipedia.org/wiki/Xerox_Network_Systems

Other/unofficial uses

some third-party databases (WhatPortIs) also list port 56 as "Route Access Protocol (RAP)," but RAP is formally port 38 per RFC 1476 — this appears to be a secondary/erroneous attribution

[Likely] — https://www.rfc-editor.org/rfc/rfc1476.html

Common software

Xerox proprietary network equipment/software (late 1970s–1980s, e.g. DocuTech publishing systems); derivative stacks (NetWare IPX/SPX, Banyan VINES, 3+Share) inherited XNS architecture but not necessarily port 56; no modern implementer known

[Likely] — https://networkencyclopedia.com/xerox-network-systems-xns/

Security implications

protocol obsolete since the 1980s; third-party databases label XNS "insecure" in general terms but cite no CVEs, exploit history, or measured scan volume for this port; internet-facing exposure expected to be negligible

[Unknown] — https://whatportis.com/ports/56_xns-xerox-network-systems-authentication

Typically seen on

legacy/obsolete Xerox-lineage systems; otherwise an anomaly worth investigating

Analyst note
An open port 56 is not a recognized modern service; treat a responsive listener as an anomaly. The RAP-on-56 label seen in some databases is incorrect — RAP is port 38.
[ 02 ] — Context

About port 56/udp.

Updated  ·  Confidence: Medium

Port 56/udp is registered with IANA as xns-auth with the description "XNS Authentication," assignee and contact both listed as Susie Armstrong, and a blank reference field — the identical assignment also covers 56/tcp, so the port is dual-registered on TCP and UDP under one service name. XNS Authentication is a component of Xerox Network Systems (XNS), the protocol suite developed at Xerox PARC in the mid-to-late 1970s that influenced much of the networking that followed. The authentication service handled identity verification for users and devices on XNS-based local networks using a challenge-response scheme, so that credentials could be checked without transmitting passwords in the clear; the same Needham-Schroeder academic foundation later underpinned MIT's Kerberos. Notably, the XNS suite ran over its own transport, the Sequenced Packet Protocol (SPP), not TCP/IP — so the IANA TCP and UDP assignment for port 56 is a historical artifact of the early port registry rather than evidence of an IP-native service. The IANA reference field is blank: no RFC is cited in the registry, and registration and modification dates are not populated. For an analyst the practical takeaway is that this is an obsolete protocol — XNS fell out of use as TCP/IP became ubiquitous, and the assignment persists mainly as a legacy record. A recurring point of confusion is that some third-party port databases instead label port 56 as "Route Access Protocol (RAP)"; that is a secondary or erroneous attribution — IANA assigns port 56 exclusively to xns-auth, and RAP (RFC 1476) is formally assigned to port 38, not 56. No Shodan datasets or documented CVEs specific to live 56/udp exposure were found, and the one scan-derived measurement available — an nmap-services open-frequency of ≈ 0.001285, roughly 1 in 1,000 sampled hosts — is low enough to be background, so any responsive port 56 today is best treated as an anomaly worth investigating rather than a recognized modern service.

IANA assignment
xns-auth — "XNS Authentication"; reference (blank — no RFC cited in IANA registry); assignee/contact Susie Armstrong; dual-registered 56/tcp + 56/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry)
Range class
well-known (0–1023) [Confirmed]
Registration / modification date
blank in IANA registry — none published [Confirmed] — IANA registry (Reference and date columns blank)
Prevalence
nmap-services observed open-frequency 56/udp ≈ 0.001285 — very low (roughly 1 in 1,000 sampled hosts), 294th of 5,615 UDP entries; the TCP sibling 56/tcp is ≈ 0.000013, about 100× lower. Because UDP scans report open|filtered when nothing answers, a figure this size is consistent with silent hosts rather than live XNS Authentication services
[Likely] — nmap-services dataset. No Shodan exposure data specific to 56/udp was found [Unknown]
Related ports
38/tcp (Route Access Protocol — the correct RAP assignment, contrast); 56/tcp (same IANA xns-auth assignment); other XNS-era assignments

Primary use

identity verification within Xerox Network Systems (XNS) LANs via a challenge-response scheme (no passwords on the wire); XNS ran over its own SPP transport, not TCP/IP, so the TCP+UDP port-56 assignment is a registry artifact

[Likely] — https://en.wikipedia.org/wiki/Xerox_Network_Systems

Other/unofficial uses

some third-party databases (e.g. WhatPortIs) list port 56 as "Route Access Protocol (RAP)," but RAP is formally port 38 per RFC 1476 — this appears to be a secondary/erroneous attribution

[Likely] — https://www.rfc-editor.org/rfc/rfc1476.html

Common software

Xerox proprietary network equipment/software (late 1970s–1980s); derivative stacks such as Novell NetWare (IPX/SPX), Banyan VINES, and AppleTalk inherited XNS architecture but did not reuse port 56 on TCP/IP; no modern implementer known to listen on 56/udp

[Likely] — https://en.wikipedia.org/wiki/Xerox_Network_Systems

Security implications

protocol obsolete since the 1980s; one third-party port database notes port 56 was historically flagged in virus/trojan listings but classifies the standard xns-auth assignment as non-malicious — no CVEs or named active exploit for this port were found; internet-facing exposure expected to be negligible, consistent with the very low nmap-services open-frequency

[Likely] — https://www.auditmypc.com/udp-port-56.asp

Typically seen on

legacy/obsolete Xerox-lineage systems; otherwise an anomaly worth investigating

Lineage note
XNS Authentication's challenge-response design traces to the Needham-Schroeder symmetric-key protocol and is the same lineage later used by Kerberos; XNS itself dates to the late 1970s [Likely] — https://www.connected.app/ckb/ports/56
Analyst note
An open port 56 is not a recognized modern service; treat a responsive listener as an anomaly. The RAP-on-56 label seen in some databases is incorrect — RAP is port 38. Because UDP is connectionless, scanners typically report 56/udp as open|filtered when nothing answers.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
xns-auth UDP XNS Authentication 0.13%
xns-auth TCP XNS Authentication 0.00%
IANA name
xns-auth
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.