Port 636: LDAPS
TCP 636 is the port for LDAP over TLS. Internal only, or restricted to known application servers.
| Service | LDAP over TLS |
|---|---|
| Protocol | TCP |
| Exposure risk | Medium: expose with care |
| Range | Well-known (0–1023): binding needs root/admin on Unix |
What port 636 does
LDAP wrapped in TLS from the start, used by applications binding to Active Directory or OpenLDAP securely.
Should port 636 be open?
Internal only, or restricted to known application servers.
Find what's listening on port 636
- Linux:
sudo ss -tulpn | grep :636 - macOS:
sudo lsof -nP -i :636 - Windows:
netstat -ano | findstr :636, then look up the PID in Task Manager.
Open or block it in a firewall
- ufw:
sudo ufw allow 636/tcp(ordeny) - firewalld:
sudo firewall-cmd --add-port=636/tcp --permanent && sudo firewall-cmd --reload - Windows:
New-NetFirewallRule -DisplayName "Port 636" -Direction Inbound -Protocol TCP -LocalPort 636 -Action Allow
Port assignment per the IANA Service Name and Transport Protocol Port Number Registry. Test several ports at once with the port scanner, or any port with the open port checker.
Questions about port 636
What is port 636 used for?
LDAP over TLS. LDAP wrapped in TLS from the start, used by applications binding to Active Directory or OpenLDAP securely.
Is port 636 TCP or UDP?
TCP. LDAPS uses TCP port 636.
Is it safe to open port 636?
Medium: expose with care. Internal only, or restricted to known application servers.
How do I check if port 636 is open?
Use the checker on this page: it connects to your host on TCP 636 from the internet. Locally, run
nc -vz host 636 (macOS/Linux) or Test-NetConnection host -Port 636 (PowerShell). To see what is listening on your own machine, run ss -tulpn | grep :636 (Linux) or netstat -ano | findstr :636 (Windows).