Port 389: LDAP

Directory lookups (users and groups). Exposed CLDAP (UDP 389) is a major amplification source. Keep directories internal; use LDAPS on 636 across networks.

  • Free
  • No Sign-Up
  • Runs in Your Browser

Examples:

Ports

1 of 41

Port Lookup

Port 389 at a glance

Port389
ProtocolTCP/UDP
ServiceLDAP
Open to the Internet?No, keep it on a private network
See What Is Listeningss -lntup | grep ':389 '
Test From Outsidenc -zv your-server 389
Block with UFWufw deny 389/tcp; ufw deny 389/udp
Block with nftablesnft add rule inet filter input meta l4proto { tcp, udp } th dport 389 drop

LDAP uses TCP/UDP port 389. Directory lookups (users and groups).

Exposed CLDAP (UDP 389) is a major amplification source. Keep directories internal; use LDAPS on 636 across networks.

If ss shows something listening on port 389 on a public address, bind it to 127.0.0.1 or a private interface in the service's own configuration, and drop the port in the firewall as well.

Questions

What is port 389 used for?
LDAP. Directory lookups (users and groups).
Is it safe to open port 389?
No, keep it on a private network. Exposed CLDAP (UDP 389) is a major amplification source. Keep directories internal; use LDAPS on 636 across networks.
How do I check if port 389 is open?
On the server, ss -lntup | grep ':389 ' shows what is listening. From another machine, nc -zv your-server 389 shows whether the firewall lets it through.
How do I block port 389?
With UFW: ufw deny 389/tcp and ufw deny 389/udp. With nftables, add a drop rule for dport 389 in your input chain.

Abuse from open ports on your VMs?

Frabs spots amplification, scans and floods leaving any VM and stops them, without touching your firewall.