Registered to ESRO, but on a real network it is usually Check Point FireWall-1 client authentication.
IANA assigns 259 to esro-gen, Efficient Short Remote Operations, a lightweight RPC-over-UDP scheme specified in RFC 2188 for low-bandwidth links; you will effectively never meet a live ESRO server. What you do meet is Check Point: TCP 259 carries FireWall-1 Client Authentication, where a user telnets to the firewall, logs in, and the firewall then opens rules for that source address. Nmap's list separately marks 259/udp as Check Point's proprietary RDP tunnelling protocol. An open 259 next to 256 and 264 is a Check Point gateway, not ESRO.
Do not expose
Check Point client authentication is an interactive login prompt on the firewall itself — a cleartext credential surface that also grants network access on success.
$ nmap -sV -p 259 TARGETSeen this on your network? Beige Box scans your Wi-Fi and shows every open port on every device — and its Ports tool links straight back here.
Get Beige Box →also available as JSON · Markdown
Corrections or a missing port? Reply @rimrocksystems.