Port 389: LDAP
TCP/UDP 389 is the port for Lightweight Directory Access Protocol. Never on the internet; CLDAP on UDP 389 has been used for amplification attacks.
| Service | Lightweight Directory Access Protocol |
|---|---|
| Protocol | TCP/UDP |
| Exposure risk | High: do not expose to the internet |
| Secure alternative | LDAPS (port 636) or StartTLS |
| Range | Well-known (0–1023): binding needs root/admin on Unix |
What port 389 does
Applications query directories such as Active Directory and OpenLDAP for users and groups on 389. On Active Directory, LDAP signing and channel binding should be enforced.
Should port 389 be open?
Never on the internet; CLDAP on UDP 389 has been used for amplification attacks. Where you can, use LDAPS (port 636) or StartTLS instead.
Find what's listening on port 389
- Linux:
sudo ss -tulpn | grep :389 - macOS:
sudo lsof -nP -i :389 - Windows:
netstat -ano | findstr :389, then look up the PID in Task Manager.
Open or block it in a firewall
- ufw:
sudo ufw allow 389/tcp(ordeny) - firewalld:
sudo firewall-cmd --add-port=389/tcp --permanent && sudo firewall-cmd --reload - Windows:
New-NetFirewallRule -DisplayName "Port 389" -Direction Inbound -Protocol TCP -LocalPort 389 -Action Allow
Port assignment per the IANA Service Name and Transport Protocol Port Number Registry. Test several ports at once with the port scanner, or any port with the open port checker.
Questions about port 389
What is port 389 used for?
Lightweight Directory Access Protocol. Applications query directories such as Active Directory and OpenLDAP for users and groups on 389. On Active Directory, LDAP signing and channel binding should be enforced.
Is port 389 TCP or UDP?
Both. LDAP uses TCP and UDP on port 389.
Is it safe to open port 389?
High: do not expose to the internet. Never on the internet; CLDAP on UDP 389 has been used for amplification attacks. Secure alternative: LDAPS (port 636) or StartTLS.
How do I check if port 389 is open?
Use the checker on this page: it connects to your host on TCP 389 from the internet. Locally, run
nc -vz host 389 (macOS/Linux) or Test-NetConnection host -Port 389 (PowerShell). To see what is listening on your own machine, run ss -tulpn | grep :389 (Linux) or netstat -ano | findstr :389 (Windows).