Port 389: Lightweight Directory Access Protocol
Port 389 is the IANA-assigned port for the Lightweight Directory Access Protocol (LDAP), defined in RFC 4511. Directory services such as Active Directory and OpenLDAP answer queries and binds on TCP 389, and Active Directory domain controllers also use UDP 389 for connectionless LDAP and the DC Locator. LDAPS uses port 636 and the Global Catalog uses ports 3268 and 3269.
Port Details
Security Exposure
LDAP on port 389 transmits data in plain text unless StartTLS is used, and an exposed server lets outsiders query user and group data or attempt credential attacks (UK Government Cyber Unit). Microsoft notes that unsigned LDAP traffic is open to replay and man-in-the-middle attacks. CISA alert TA14-017A lists LDAP and CLDAP as UDP reflection vectors with amplification factors of 46 to 55 and 56 to 70.
Hardening
- +Block TCP and UDP 389 from the internet and allow it only from trusted internal networks.
- +Require LDAP signing on Active Directory domain controllers and clients through Group Policy.
- +Use LDAPS on port 636 or StartTLS (RFC 4513) for any simple bind.
- +Disable anonymous binds in the directory configuration.
Monitoring
On Active Directory, review Event ID 2887 (daily count of unsigned or cleartext binds) and enable Event ID 2889 to log the client address and identity behind each one. Alert on LDAP traffic from untrusted networks and on large UDP 389 responses.
Tools for Auditing and Monitoring LDAP
BloodHound CE
Free / CommercialAttack path analysis platform that maps identity and privilege relationships across Active Directory, Entra ID, and other platforms through OpenGraph.
NetExec
Open SourceNetwork service assessment tool for automating authentication checks, credential sprays, and Active Directory evaluations.
Impacket
FreePython library of classes and example tools for the construction, parsing, and interaction with Windows and Active Directory network protocols.
Related Tool Categories
Secrets managers, identity engines, and access control platforms for managing credentials and privilege.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
SIEM platforms, EDR agents, SOAR automation, and detection rule engines for security operations.
Frequently Asked Questions
Is LDAP TCP or UDP?→
LDAP normally uses TCP 389. IANA also registers UDP 389, which Active Directory uses for connectionless LDAP requests such as DC Locator.
What is the difference between port 389 and port 636?→
Port 389 is standard LDAP, unencrypted unless StartTLS is used. Port 636 is LDAPS, which runs LDAP over TLS.
Should port 389 be open to the internet?→
No. UK Government Cyber Unit guidance says LDAP needs to be reachable inside the organization but should not be visible externally.
Sources
- IANA Service Name and Transport Protocol Port Number Registry (port 389)
- RFC 4511: Lightweight Directory Access Protocol (LDAP): The Protocol
- RFC 4513: LDAP: Authentication Methods and Security Mechanisms
- Microsoft Learn: Service overview and network port requirements for Windows
- Microsoft Learn: How to enable LDAP signing in Windows Server
- Microsoft Learn: cldap_open function (winldap.h)
- UK Government Cyber Unit: Open port 389, Lightweight Directory Access Protocol (LDAP)
- CISA Alert TA14-017A: UDP-Based Amplification Attacks
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 389 is not guaranteed to be LDAP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).