Summary

  • RFC 9900 is an IETF Proposed Standard that de-assigns the TCP and UDP bindings for port 831, used by NETCONF over BEEP, and ports 832 and 833, used by NETCONF over SOAP variants.
  • The action is deliberately narrow: it removes the port-number assignments, keeps the service names, and records historical notes against all three numbers.
  • RFC 4743 and RFC 4744 are Historic. RFC 9900 describes these assignments as supporting protocols with no known implementations or production deployments; that is an evidence boundary, not a claim that every NETCONF transport is obsolete.

The mechanism matters because a registry number has a longer operational afterlife than a protocol design. A literal 831, 832, or 833 may remain in an old diagram, an allow-list, a service database, or a configuration template. RFC 9900 does not pretend those references vanish. It makes the IANA registry accurate again while retaining the names netconf-beep, netconfsoaphttp, and netconfsoapbeep, plus notes that the numbers were formerly assigned to the relevant NETCONF transports and released by RFC 9900.

The removed entries cover both TCP and UDP rows. Port 831 is associated with NETCONF over BEEP; ports 832 and 833 identify the SOAP-related variants. The RFC is a registry-maintenance action, not a new protocol, and it states that it introduces no new security vulnerability. It also does not de-assign NETCONF over SSH on 830, NETCONF Call Home on 4334, or NETCONF over TLS on 6513.

RFC 6335 supplies the stewardship logic. Port numbers are the scarce resource, while service names should remain assigned after a port assignment is de-assigned because exhaustion of names presents much less danger. A de-assigned number is marked Reserved and should not be reassigned until every other available port in the relevant range has been assigned. Thus 831–833 are not immediately free for arbitrary use, and RFC 9900 announces no reassignment schedule.

For operators, RFC 9900 asks for a limited reassessment of configurations that still associate released numbers with netconf-beep or netconfsoaphttp. It adds no other operational or manageability requirements and prescribes no organization-wide audit timetable. The practical decision is to verify what a local system actually uses, rather than infer current behavior from a registry label.

Theo March analysis — not an RFC mandate: treat this as lifecycle control. Inventory literal-number dependencies separately from name-based discovery; compare service files, filters, diagrams, and configuration repositories; then assign ownership for removing obsolete assumptions. Name persistence can preserve semantic discovery, while literal-number references are where configuration drift can survive. This analysis does not assert that such references exist in any measured population.

Sources