Port 1994Cisco STUN-SDLC

Cisco's Serial Tunnel (STUN) with Synchronous Data Link Control (SDLC) is a protocol used primarily to encapsulate mainframe SNA traffic over IP networks. It facilitates bridging traditional serial synchronous protocols across routed IP infrastructure, enabling mainframe communications over modern networking topologies without changing legacy host configurations..

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
6,426

rank 787 of 993 · top 79%

Technical Details

what runs on :1994

Cisco STUN-SDLC is designed to transport SDLC frames, which are typically exchanged between IBM mainframes and remote devices, over IP networks. It encapsulates traditional SDLC bit streams within TCP or UDP packets, allowing these legacy synchronous protocols to pass through routed or switched Ethernet networks rather than dedicated serial lines.

This encapsulation approach maintains the integrity of synchronous data transmissions, supporting full SDLC frame control and addressing. As a result, enterprises can continue using their mainframe communications without hardware changes, leveraging existing Cisco routing infrastructure to interconnect remote SNA devices or branch controllers across their WAN.

STUN-SDLC supports both point-to-point and multipoint connections, and it is compatible with various Cisco routers implementing SNA encapsulation strategies. This technology was an important step in bridging traditional IBM networking with emerging IP-based transport during the transition from pure SNA to IP networks.

Security Information

exposure of :1994

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common Vulnerabilities:

  • Since STUN-SDLC transmits encapsulated mainframe data over IP, it is susceptible to interception, eavesdropping, and replay attacks if the traffic is unencrypted.
  • The protocol relies on encapsulation but lacks inherent encryption, making it vulnerable to packet sniffing.
  • Potential denial-of-service (DoS) risks exist if port 1994 is exposed without filters, as attackers can flood or disrupt the encapsulated flows.

Common Mitigations:

  • Deploy strong network segmentation and firewall rules to strictly limit access to trusted hosts.
  • Use IPsec or other tunneling encryption methods to secure the encapsulated SDLC traffic.
  • Monitor for unusual activity and implement rate-limiting on this port to prevent flooding attempts.
  • Decommission open STUN-SDLC interfaces if no longer required, especially when migrating fully to IP-based protocols without SNA dependencies.

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted