Port 711Cisco Tag Distribution
Cisco Tag Distribution Protocol (TDP) was an early Cisco-proprietary protocol used primarily for exchanging MPLS label bindings between routers in a network. Though it provided foundational MPLS label distribution capabilities, it has largely been superseded by the standardized Label Distribution Protocol (LDP), which offers enhanced compatibility and interoperability across diverse vendor environments..
- transport
- tcp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 5,000
single transport
payload readable on path
registered with iana
caution
rank 921 of 993 · top 93%
Technical Details
what runs on :711Cisco Tag Distribution Protocol (TDP) is a Cisco-developed protocol that facilitates the binding and propagation of MPLS labels between adjacent routers. It establishes sessions over TCP, ensuring reliable delivery of label mapping information necessary for efficient label switched path (LSP) setup within an MPLS-enabled infrastructure.
TDP operates by exchanging labels associated with IP prefixes so that routers can quickly switch packets based on short labels instead of long network addresses. This mechanism streamlines packet forwarding, reduces processing overhead, and supports advanced MPLS features such as traffic engineering and VPN services. Despite its proprietary nature, it played a crucial role in early MPLS implementations, especially within Cisco-heavy deployments.
Over time, TDP has been phased out in favor of the Internet Engineering Task Force's Label Distribution Protocol (LDP). LDP is an open standard, enabling broader multi-vendor interoperability and support. Modern Cisco devices default to LDP, encouraging migrations from legacy TDP deployments for more standardized operations.
Security Information
exposure of :711risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
network services averages 3.9 across 604 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp
every listening transport is another surface to filter at the edge
security overview
Common security vulnerabilities associated with TDP include:
- Unauthorized Access: Due to the lack of strong authentication mechanisms in the original TDP implementations, malicious actors could potentially intercept or inject false label mappings, leading to traffic disruption or redirection.
- Session Hijacking: Unencrypted sessions are susceptible to man-in-the-middle attacks, which might manipulate MPLS forwarding behaviors.
- DoS Attacks: Attackers may target label distribution processes, overwhelming routers' control planes and impairing network stability.
Mitigations involve:
- Migration to LDP: Use standardized and more secure protocols supporting enhanced authentication.
- Control Plane Policing: Implement ACLs or infrastructure access lists to restrict label protocol communication strictly to authorized peers.
- Encryption: Employ technologies like IPsec to secure label distribution sessions.
- Monitoring: Continuously monitor MPLS control plane activity for anomalies and unauthorized changes.
- Vendor Best Practices: Follow Cisco's security guidelines for MPLS deployments and ensure software is up to date to patch known vulnerabilities.
Related Ports
the 8 most looked-up other ports in network services — 604 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :6543 | Jetnet | UDP | Network Services | caution | 65.3k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3233 | WhiskerControl Protocol | TCPUDP | Network Services | caution | 61.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Tatsoft Default HTTP Proxy | TCP | Web Services | caution | 46.8k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted