Port 1994Cisco STUN-SDLC
Cisco's Serial Tunnel (STUN) with Synchronous Data Link Control (SDLC) is a protocol used primarily to encapsulate mainframe SNA traffic over IP networks. It facilitates bridging traditional serial synchronous protocols across routed IP infrastructure, enabling mainframe communications over modern networking topologies without changing legacy host configurations..
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 6,426
2 transports registered
payload readable on path
registered with iana
caution
rank 787 of 993 · top 79%
Technical Details
what runs on :1994Cisco STUN-SDLC is designed to transport SDLC frames, which are typically exchanged between IBM mainframes and remote devices, over IP networks. It encapsulates traditional SDLC bit streams within TCP or UDP packets, allowing these legacy synchronous protocols to pass through routed or switched Ethernet networks rather than dedicated serial lines.
This encapsulation approach maintains the integrity of synchronous data transmissions, supporting full SDLC frame control and addressing. As a result, enterprises can continue using their mainframe communications without hardware changes, leveraging existing Cisco routing infrastructure to interconnect remote SNA devices or branch controllers across their WAN.
STUN-SDLC supports both point-to-point and multipoint connections, and it is compatible with various Cisco routers implementing SNA encapsulation strategies. This technology was an important step in bridging traditional IBM networking with emerging IP-based transport during the transition from pure SNA to IP networks.
Security Information
exposure of :1994risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
network services averages 3.9 across 604 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
Common Vulnerabilities:
- Since STUN-SDLC transmits encapsulated mainframe data over IP, it is susceptible to interception, eavesdropping, and replay attacks if the traffic is unencrypted.
- The protocol relies on encapsulation but lacks inherent encryption, making it vulnerable to packet sniffing.
- Potential denial-of-service (DoS) risks exist if port 1994 is exposed without filters, as attackers can flood or disrupt the encapsulated flows.
Common Mitigations:
- Deploy strong network segmentation and firewall rules to strictly limit access to trusted hosts.
- Use IPsec or other tunneling encryption methods to secure the encapsulated SDLC traffic.
- Monitor for unusual activity and implement rate-limiting on this port to prevent flooding attempts.
- Decommission open STUN-SDLC interfaces if no longer required, especially when migrating fully to IP-based protocols without SNA dependencies.
Related Ports
the 8 most looked-up other ports in network services — 604 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :6543 | Jetnet | UDP | Network Services | caution | 65.3k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3233 | WhiskerControl Protocol | TCPUDP | Network Services | caution | 61.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Tatsoft Default HTTP Proxy | TCP | Web Services | caution | 46.8k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted