10-13-2004 10:35 AM - edited 03-02-2019 07:13 PM
While working on something else I discovered that all of our 1700 routers (1720, 1750, 1751) are listening on port tcp/2005. IANA lists this as "berknet". They are all running 12.2 or 12.3 IOS with feature sets ranging from IP Basic to IP/3DES/FW/IDS/etc. None of our other Cisco router models (831, 2600, 3600, 7200) are doing this.
Can anybody confirm that their 1700's are acting the same and can anybody explain this?
Thanks,
Bob
Solved! Go to Solution.
10-13-2004 12:22 PM
Most likely port 2005 is the port number your 1700 series router uses if you want to reverse telnet to a modem on your AUX port. That number is derived from 2000 + "n" on the access server, where "n" is the line number to which the modem is connected. Do a "show line" command on your router, the AUX port is probably Tty 5 so 2000+5=2005.
See this link for more details:
Establishing a Reverse Telnet Session to a Modem
I have a 1720 that I use the AUX port as an asynchronous serial port on, which directly connects to a machine at 9600,N,8,1 to control the direction of a satellite dish. The TCP port number I telnet into on that router so I can issue commands to the dish controller is 2005. Same as what you're seeing.
The reason you're not seeing that specific port number on your other routers (831, 2600, 3600, 7200) is because they are probably using different line numbers for AUX. Here's a sampling of what I found on some of my routers:
2610, 2620, 2651: AUX was line 65 on each (so there was a corresponding TCP port 2065)
3640: AUX was line 129 (TCP port was 2129)
7206VXR: AUX was 1 (TCP port was 2001)
Check your other routers for the line number they assign to the AUX port. There should be a matching TCP port at 2000+AUXlinenumber.
Hope this helps.
10-13-2004 11:29 AM
One thing I found is that tcp port 2005 is used with the CSWinAgent and listens for Cisco Secure ACS Solution Engine messages. Of course this is with windows machines but I suspect this might be what the 1700 is listening for too.
10-13-2004 12:22 PM
Most likely port 2005 is the port number your 1700 series router uses if you want to reverse telnet to a modem on your AUX port. That number is derived from 2000 + "n" on the access server, where "n" is the line number to which the modem is connected. Do a "show line" command on your router, the AUX port is probably Tty 5 so 2000+5=2005.
See this link for more details:
Establishing a Reverse Telnet Session to a Modem
I have a 1720 that I use the AUX port as an asynchronous serial port on, which directly connects to a machine at 9600,N,8,1 to control the direction of a satellite dish. The TCP port number I telnet into on that router so I can issue commands to the dish controller is 2005. Same as what you're seeing.
The reason you're not seeing that specific port number on your other routers (831, 2600, 3600, 7200) is because they are probably using different line numbers for AUX. Here's a sampling of what I found on some of my routers:
2610, 2620, 2651: AUX was line 65 on each (so there was a corresponding TCP port 2065)
3640: AUX was line 129 (TCP port was 2129)
7206VXR: AUX was 1 (TCP port was 2001)
Check your other routers for the line number they assign to the AUX port. There should be a matching TCP port at 2000+AUXlinenumber.
Hope this helps.
10-13-2004 01:35 PM
Thanks, that does help. And it confirms what I was beginning to discover.
Bob
10-13-2004 01:32 PM
I did some more digging and found that this port is open as a result of enabling telnet as an input transport on the aux 0 line.
Interestingly, the same command produces different results on different platforms. On 2600, 3600 and 7200 routers no ports are opened when telnet is enabled on the aux 0 line. On 7100 routers the tcp/2001 port is opened.
At any rate, I answered my own question. Any comments or additional information is welcome.
Bob
10-13-2004 02:37 PM
It is not that the behavior is different on the other platforms, it is just that the line number assigned to the auxiliary port differs from one platform to the other. This basically means that on these other platforms a different TCP port would be listening for connections. For examples, on the 2600 the aux port is assigned to line 65, which means that TCP port 2065 listens for reverse telnet connections to the aux port.
To see what line number the aux port is assigned to, use the "show line" command.
Hope this helps,
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide