Port 1967Cisco IP SLA Control
Cisco IOS IP Service Level Agreements (IP SLAs) Control Protocol enables network performance monitoring by defining, configuring, scheduling, and collecting statistics about network operations tests. It allows administrators to measure metrics such as latency, jitter, packet loss, and availability directly through Cisco devices, providing valuable insights into real-time network health and SLA compliance..
- transport
- udp
- in transit
- cleartext
- assignment
- unofficial
- risk
- 4/10
- lookups
- 13,182
single transport
payload readable on path
used by convention
caution
rank 282 of 993 · top 28%
Technical Details
what runs on :1967Cisco IOS IP Service Level Agreements (IP SLAs) Control Protocol operates primarily over UDP port 1967 to facilitate management and communication of IP SLA operations on Cisco devices. Network administrators utilize IP SLAs to create specific performance monitoring tasks—such as measuring round-trip time, jitter, packet loss, and response times for various protocols including ICMP, UDP, TCP, HTTP, and DNS.
The Control Protocol is designed to distribute configuration commands and collect measurement results from the target Cisco devices. The protocol exchanges management frames to initiate, monitor, and terminate various SLA tests running on the routers or switches, ensuring accurate measurement cycles.
Data gathered via the control protocol feeds into network management systems (NMS), which then interpret this for trend analysis, SLA verification, or real-time alerts. This enables proactive network management and helps in quick identification of degradation points, facilitating timely troubleshooting.
Security Information
exposure of :1967risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
network services averages 3.9 across 604 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
unofficial
used by convention, not registered — what answers here varies by deployment
reachable over
udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
Common Vulnerabilities:
- Exposure of the UDP port 1967 on unprotected interfaces can lead to unauthorized control or manipulation of IP SLA configurations on Cisco devices.
- Attackers could perform spoofing or DoS attacks targeting IP SLA control communication due to its lack of inherent encryption or strong authentication.
- Poorly secured access may allow attackers to cause resource exhaustion or gather sensitive network performance data.
Common Mitigations:
- Restrict UDP port 1967 access using ACLs and firewall rules to trusted management hosts.
- Utilize secure management protocols (SSH, SNMPv3) along with IP SLAs.
- Regularly update device firmware to patch any protocol weaknesses.
- Segment management traffic using dedicated VLANs or out-of-band channels.
- Enable device authentication and user access controls to prevent unauthorized changes to IP SLA configurations.
Related Ports
the 8 most looked-up other ports in network services — 604 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :6543 | Jetnet | UDP | Network Services | caution | 65.3k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3233 | WhiskerControl Protocol | TCPUDP | Network Services | caution | 61.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Tatsoft Default HTTP Proxy | TCP | Web Services | caution | 46.8k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted