WHATPORT(2106) whatport.net WHATPORT(2106)
2106

MZAP / ekshell

MZAP's multicast scope announcements on UDP; historically Kerberos encrypted rshell on TCP.

TCP UDP IANA registry

Description

RFC 2776 defines the Multicast-Scope Zone Announcement Protocol here: routers on a scope boundary send Zone Announcement Messages to UDP 2106 at the local-scope group 239.255.255.252 so hosts can discover administrative scope zones and operators can spot misconfigured boundaries. That traffic is multicast infrastructure, not something a host offers. Unix /etc/services and Nmap also list ekshell on TCP 2106, the encrypted Kerberos remote-shell counterpart to eklogin, which MIT moved out of krb5 along with the rest of the Kerberized applications.

Exposed to the internet?

Expose with care

MZAP is scoped multicast that is not meant to cross a zone boundary at all. A TCP listener here is something else — historically a Kerberized rshell daemon — and should be identified and kept internal.

Check it yourself

$ sudo tcpdump -ni any udp port 2106

See also

Seen this on your network? Beige Box scans your Wi-Fi and shows every open port on every device — and its Ports tool links straight back here.

Get Beige Box →

also available as JSON · Markdown

Corrections or a missing port? Reply @rimrocksystems.