Port 1991Cisco STUN Priority 2

Cisco STUN Priority 2 traffic uses TCP or UDP port 1991.

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
5/10

caution

lookups
0

rank 993 of 5,526 · top 18%

also known as stun-p2

Technical Details

what runs on :1991

Cisco STUN encapsulates serial traffic, such as SDLC or other supported serial link protocols, inside Cisco-to-Cisco IP tunnel traffic. It can use TCP or UDP; port 1991 is the registered Priority 2 service in the Cisco STUN family, alongside separate priority assignments on nearby ports. The protocol is Cisco-specific rather than RFC 5389 Session Traversal Utilities for NAT, and normal deployments do not provide encryption.

Security Information

exposure of :1991

risk score

5/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 2.6 across 1,653 ports — this one sits 2.4 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Internet exposure is generally inappropriate: an exposed listener may permit unauthorized tunnel establishment or access to attached serial devices if Cisco STUN configuration and peer restrictions are weak. Traffic is normally cleartext and can expose or transport sensitive control traffic, so restrict the port to known router peers with filtering and use a protected network or encrypted tunnel.

the 8 most looked-up other ports in network services — 1,653 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted