Skip to main content

Port Details

Port
389
Transport
TCP / UDP
Service
LDAP
IANA service name
ldap
Range
System port (0-1023)
Related ports

Security Exposure

LDAP on port 389 transmits data in plain text unless StartTLS is used, and an exposed server lets outsiders query user and group data or attempt credential attacks (UK Government Cyber Unit). Microsoft notes that unsigned LDAP traffic is open to replay and man-in-the-middle attacks. CISA alert TA14-017A lists LDAP and CLDAP as UDP reflection vectors with amplification factors of 46 to 55 and 56 to 70.

Hardening

  • +Block TCP and UDP 389 from the internet and allow it only from trusted internal networks.
  • +Require LDAP signing on Active Directory domain controllers and clients through Group Policy.
  • +Use LDAPS on port 636 or StartTLS (RFC 4513) for any simple bind.
  • +Disable anonymous binds in the directory configuration.

Monitoring

On Active Directory, review Event ID 2887 (daily count of unsigned or cleartext binds) and enable Event ID 2889 to log the client address and identity behind each one. Alert on LDAP traffic from untrusted networks and on large UDP 389 responses.

Tools for Auditing and Monitoring LDAP

BloodHound CE

Free / Commercial
Red Teaming Tools

Attack path analysis platform that maps identity and privilege relationships across Active Directory, Entra ID, and other platforms through OpenGraph.

LicenseApache-2.0
PlatformLinux, macOS, Windows

NetExec

Open Source
Penetration Testing Tools

Network service assessment tool for automating authentication checks, credential sprays, and Active Directory evaluations.

LicenseBSD-2-Clause
PlatformLinux, macOS, Windows
Penetration Testing Tools

Python library of classes and example tools for the construction, parsing, and interaction with Windows and Active Directory network protocols.

LicenseModified Apache-1.1 (custom; see repo LICENSE)
PlatformLinux, macOS, Windows

Frequently Asked Questions

Is LDAP TCP or UDP?→

LDAP normally uses TCP 389. IANA also registers UDP 389, which Active Directory uses for connectionless LDAP requests such as DC Locator.

What is the difference between port 389 and port 636?→

Port 389 is standard LDAP, unencrypted unless StartTLS is used. Port 636 is LDAPS, which runs LDAP over TLS.

Should port 389 be open to the internet?→

No. UK Government Cyber Unit guidance says LDAP needs to be reachable inside the organization but should not be visible externally.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 389 is not guaranteed to be LDAP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).