Port 1967Cisco IP SLA Control

Cisco IOS IP Service Level Agreements (IP SLAs) Control Protocol enables network performance monitoring by defining, configuring, scheduling, and collecting statistics about network operations tests. It allows administrators to measure metrics such as latency, jitter, packet loss, and availability directly through Cisco devices, providing valuable insights into real-time network health and SLA compliance..

transport
udp

single transport

in transit
cleartext

payload readable on path

assignment
unofficial

used by convention

risk
4/10

caution

lookups
13,182

rank 282 of 993 · top 28%

Technical Details

what runs on :1967

Cisco IOS IP Service Level Agreements (IP SLAs) Control Protocol operates primarily over UDP port 1967 to facilitate management and communication of IP SLA operations on Cisco devices. Network administrators utilize IP SLAs to create specific performance monitoring tasks—such as measuring round-trip time, jitter, packet loss, and response times for various protocols including ICMP, UDP, TCP, HTTP, and DNS.

The Control Protocol is designed to distribute configuration commands and collect measurement results from the target Cisco devices. The protocol exchanges management frames to initiate, monitor, and terminate various SLA tests running on the routers or switches, ensuring accurate measurement cycles.

Data gathered via the control protocol feeds into network management systems (NMS), which then interpret this for trend analysis, SLA verification, or real-time alerts. This enables proactive network management and helps in quick identification of degradation points, facilitating timely troubleshooting.

Security Information

exposure of :1967

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

unofficial

used by convention, not registered — what answers here varies by deployment

reachable over

udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common Vulnerabilities:

  • Exposure of the UDP port 1967 on unprotected interfaces can lead to unauthorized control or manipulation of IP SLA configurations on Cisco devices.
  • Attackers could perform spoofing or DoS attacks targeting IP SLA control communication due to its lack of inherent encryption or strong authentication.
  • Poorly secured access may allow attackers to cause resource exhaustion or gather sensitive network performance data.

Common Mitigations:

  • Restrict UDP port 1967 access using ACLs and firewall rules to trusted management hosts.
  • Utilize secure management protocols (SSH, SNMPv3) along with IP SLAs.
  • Regularly update device firmware to patch any protocol weaknesses.
  • Segment management traffic using dedicated VLANs or out-of-band channels.
  • Enable device authentication and user access controls to prevent unauthorized changes to IP SLA configurations.

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted