Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

UDP Ports Open on Device

As a public utility, we must comply with a host of network requirements handed down by NERC. One of these is the documentation of 'open' ports on network devices. That is to say, a tcp or udp port that the device is listening on or will accept connections on. A useful command for this kind of investigation is 'show control-plane host open-ports'; the output of which is shown here:

Active internet connections (servers and established)

Prot               Local Address             Foreign Address                  Service    State

tcp                        *:23                         *:0                   Telnet   LISTEN

tcp                        *:23          167.239.80.1:59714                   Telnet ESTABLIS

udp                     *:50162                         *:0                  IP SNMP   LISTEN

udp                     *:54154            10.92.192.67:514                   Syslog ESTABLIS

udp                       *:123                         *:0                      NTP   LISTEN

udp                      *:4500                         *:0                   ISAKMP   LISTEN

udp                       *:161                         *:0                  IP SNMP   LISTEN

udp                       *:162                         *:0                  IP SNMP   LISTEN

udp                      *:1975                         *:0                      IPC   LISTEN

udp                       *:500                         *:0                   ISAKMP   LISTEN

It is my understanding that enabling SNMP management of the device will result in the line above with port 50162. However, this is a random high port that is different on every device tested - see below for other examples:

udp                     *:54006                         *:0                  IP SNMP   LISTEN

udp                     *:52786                         *:0                  IP SNMP   LISTEN

I am hoping to find out what the defind range for these ports might be so that we can document appropriately?

1 REPLY
Cisco Employee

UDP Ports Open on Device

It can be any port that isn't reserved.  The reserved ports go up to 1024.  The port number allocated is randomized for security.

461
Views
0
Helpful
1
Replies
CreatePlease login to create content