Port 636: LDAPS

TCP 636 is the port for LDAP over TLS. Internal only, or restricted to known application servers.

Port 636 at a glance
ServiceLDAP over TLS
ProtocolTCP
Exposure riskMedium: expose with care
RangeWell-known (0–1023): binding needs root/admin on Unix

Your public IP is pre-filled. The test connects over TCP from NetKit's server, so it shows what the internet sees.

What port 636 does

LDAP wrapped in TLS from the start, used by applications binding to Active Directory or OpenLDAP securely.

Should port 636 be open?

Internal only, or restricted to known application servers.

Find what's listening on port 636

  • Linux: sudo ss -tulpn | grep :636
  • macOS: sudo lsof -nP -i :636
  • Windows: netstat -ano | findstr :636, then look up the PID in Task Manager.

Open or block it in a firewall

  • ufw: sudo ufw allow 636/tcp (or deny)
  • firewalld: sudo firewall-cmd --add-port=636/tcp --permanent && sudo firewall-cmd --reload
  • Windows: New-NetFirewallRule -DisplayName "Port 636" -Direction Inbound -Protocol TCP -LocalPort 636 -Action Allow

Port assignment per the IANA Service Name and Transport Protocol Port Number Registry. Test several ports at once with the port scanner, or any port with the open port checker.

Questions about port 636

What is port 636 used for?
LDAP over TLS. LDAP wrapped in TLS from the start, used by applications binding to Active Directory or OpenLDAP securely.
Is port 636 TCP or UDP?
TCP. LDAPS uses TCP port 636.
Is it safe to open port 636?
Medium: expose with care. Internal only, or restricted to known application servers.
How do I check if port 636 is open?
Use the checker on this page: it connects to your host on TCP 636 from the internet. Locally, run nc -vz host 636 (macOS/Linux) or Test-NetConnection host -Port 636 (PowerShell). To see what is listening on your own machine, run ss -tulpn | grep :636 (Linux) or netstat -ano | findstr :636 (Windows).

← Port 587 (SMTP submission) · Port 853 (DNS over TLS) →