MZAP's multicast scope announcements on UDP; historically Kerberos encrypted rshell on TCP.
RFC 2776 defines the Multicast-Scope Zone Announcement Protocol here: routers on a scope boundary send Zone Announcement Messages to UDP 2106 at the local-scope group 239.255.255.252 so hosts can discover administrative scope zones and operators can spot misconfigured boundaries. That traffic is multicast infrastructure, not something a host offers. Unix /etc/services and Nmap also list ekshell on TCP 2106, the encrypted Kerberos remote-shell counterpart to eklogin, which MIT moved out of krb5 along with the rest of the Kerberized applications.
Expose with care
MZAP is scoped multicast that is not meant to cross a zone boundary at all. A TCP listener here is something else — historically a Kerberized rshell daemon — and should be identified and kept internal.
$ sudo tcpdump -ni any udp port 2106Seen this on your network? Beige Box scans your Wi-Fi and shows every open port on every device — and its Ports tool links straight back here.
Get Beige Box →also available as JSON · Markdown
Corrections or a missing port? Reply @rimrocksystems.