- Complete list of TCP and UDP ports for roles in Windows Server & Hosting
- Recommended configurations and security practices for RDP, DNS, and Active Directory
- How to protect your network by limiting unnecessary ports and applying them according to role
- Details about the protocol each service uses and how to open or monitor ports
Managing a Windows Server- based network requires a precise understanding of which ports must be open for services to function correctly. From enabling remote login and ensuring user authentication to correctly resolving domain names, various protocols rely on specific ports to operate. To manage these ports effectively, it's helpful to consult information about network port types.
Whether you're setting up an Active Directory (AD) server , a DNS server , or enabling Remote Desktop (RDP) access , port forwarding is crucial. Improper port forwarding can lead to connection failures, authentication problems, or even compromise the security of your infrastructure if more ports than necessary are left open.
General concepts about protocols and ports in Windows Server

Windows Server uses a wide variety of services that require open TCP and UDP ports . These ports enable communication between different devices and services within the network and even externally. The two main protocols used on these ports are TCP (Transmission Control Protocol) and UDP (User Datagram Protocol).
TCP is characterized as a connection-oriented protocol that is reliable and guarantees that all packets arrive in the correct order. Therefore, it is used in services that require stability, such as HTTP, FTP, and RDP. On the other hand, UDP is faster but less reliable, which is why it is chosen for services like DNS, streaming , online gaming, etc.
In addition, ports are classified into:
- Well-known ports (0-1023): Used by standard protocols such as HTTP (80), DNS (53) or SSH (22).
- Registered ports (1024-49151): Created for less common services or applications. They may be registered by companies.
- Dynamic or ephemeral ports (49152-65535): Used by the system when a client initiates a connection. Also known as random or temporary ports.
Ports used by Active Directory (AD)
Active Directory is the heart of any Windows-based domain network. For its services to function correctly, it's essential to open several key ports, primarily related to the LDAP, Kerberos, and RPC protocols . You can find additional information on how to communicate with these services in various configurations.
Among the most important we have:
- TCP/UDP 389: This is the port used by LDAP (Lightweight Directory Access Protocol). It is prioritized for user authentication and directory replication.
- TCP 636: Used for LDAP over SSL (LDAPS).
- TCP/UDP 88: Associated with the Kerberos protocol, used for authentication.
- TCP 445: Used by SMB for file and printer sharing.
- TCP 135: RPC endpoint mapper.
- TCP 3268 / 3269: Global Catalog (GC). 3268 for searches, and 3269 when a secure connection (SSL) is required.
- TCP 9389: Active Directory Web Services (ADWS).
- TCP/UDP 53: Port for DNS resolution.
- TCP 49152–65535: RPC dynamic port range.
These ports must be available on all domain controllers and systems that interact with Active Directory. Additionally, if you work with domain controllers in different sites or networks, ensure that these ports are enabled between locations.
Ports required for Remote Desktop (RDP)
Remote Desktop (RDP) is one of the most frequently used features in Windows Server environments. Its default port is TCP 3389 , although this can be changed for security reasons. Maintaining secure access is crucial for protecting your network.
Depending on the infrastructure and the number of roles deployed (such as RD Gateway, RD Licensing, RD Session Host, etc.), the required ports vary. Here are the essential ones:
- TCP/UDP 3389: Default RDP port.
- TCP 443: If Remote Desktop via Web (RDWeb) or Gateway is used, it is encapsulated in HTTPS.
- UDP 3391: RDP traffic over UDP, more efficient if used with a Gateway.
- TCP 5504: Communication between Web Access and Connection Broker.
- TCP 5985: For administration via PowerShell and WMI.
- TCP 445: SMB communication between license server and host.
- TCP 139 / UDP 137-138: NetBIOS services used in legacy environments.
- TCP 49152–65535: Dynamic use by RPC.
These ports must be opened depending on the specific role implemented within the RDS server. If you are using internet connections or load balancers, RD Gateway becomes an ideal option for encapsulating RDP in HTTPS and avoiding problems with firewalls or NATs.
Ports for DNS servers
DNS (Domain Name System) allows computers within or outside the network to resolve domain names like "server.contoso.local" to IP addresses. Make sure it's configured correctly; you can learn more about how DNS servers work.
The key ports for this service are:
- UDP 53: For most DNS queries.
- TCP 53: It is used when the response exceeds the size of a UDP packet or for zone-to-zone transfers between DNS servers.
As with all services, it's a good idea to keep ports open only on computers that act as DNS servers, and apply firewall rules to filter access from unauthorized networks.
Ports for DHCP and WINS
In networks where IP addresses are dynamically assigned via DHCP , it is necessary to allow certain ports:
- UDP 67: Listened to by DHCP server.
- UDP 68: Used by clients to receive configuration.
WINS, although deprecated, can still be present in legacy environments with legacy applications:
- UDP 137: NetBIOS name resolution.
- UDP 138: NetBIOS datagram services.
- TCP 139: NetBIOS sessions.
If you are not using these services, it is highly recommended that you disable them and close the corresponding ports to prevent vulnerabilities. You can also learn how to properly manage USB devices as part of your overall system security.
Ports required for print servers
Print servers can also be a point of exposure if unused ports are left open. Therefore, if you manage print queues through Windows Server, make sure these ports are active:
- TCP 135: PRC.
- UDP 137-138: NetBIOS required for printer sharing on legacy networks.
- TCP 139: NetBIOS over TCP communication.
- TCP 445: SMB protocol for sharing files and printers.
It's also a good idea to open dynamically high ports used by the RPC protocol (49152–65535) if you plan to remotely manage the print server. Managing these ports can be crucial for smooth and secure operation.
Time Service Ports (NTP/SNTP)
Windows Server includes the Windows Time service (W32Time) by default, which synchronizes the system clock with external sources or domain controllers. Maintaining accurate time is essential for system security and functionality.
The ports for this service are:
- UDP 123: Port used by NTP and SNTP.
This port must be open if the server synchronizes with an external time source, or if other computers on the network use it as a time reference.
Ports for email services (SMTP, POP3, IMAP)
If you have a mail server, such as Microsoft Exchange or another Windows Server-based server, you need to open:
- TCP 25: SMTP (mail sending).
- TCP 465 / 587: SMTP with SSL or TLS.
- TCP 110: POP3.
- TCP 995: POP3 with SSL.
- TCP 143: IMAP.
- TCP 993: IMAP with SSL.
The recommendation is to use encrypted ports and remove or block ports associated with unsecured protocols to maintain the integrity of your communications. You can learn more about operating system management in Windows 11.
Ports for web services in IIS
If your server hosts web pages using Internet Information Services (IIS) , then you will need to open the following ports in your firewall:
- TCP 80: HTTP (no encryption).
- TCP 443: HTTPS (SSL/TLS encryption).
- TCP 8080: Alternative port for HTTP, commonly used in development or administration.
It's important to have valid certificates to ensure HTTPS traffic runs smoothly and avoid security warnings in your browser. Remember, when managing your servers, it's essential to have extensive knowledge of open ports to avoid vulnerabilities.
How to view and check which ports are open in Windows Server
From the system itself you can use several methods:
- netstat -an: Displays all active connections and listening ports.
- Get-NetTCPConnection (PowerShell): Very useful for listing active TCP connections.
- telnet : Check if a port is accessible from another computer.
- Test-NetConnection: More modern PowerShell command for testing connectivity.
Example:
Test-NetConnection -ComputerName servidor.contoso.local -Port 3389
You can also use nmap from another machine to scan a range of ports, which is ideal for audits. For effective scanning and monitoring, consider reading about monitoring software that can help you better manage your resources.
Dangerous or commonly exploited ports
There are ports that have historically been the target of massive attacks. Some examples:
- TCP 3389: RDP has been brute-force attacked in many ransomware campaigns.
- TCP 445: Exploited by malware like WannaCry.
- TCP 23: Telnet, without encryption, should never be exposed.
- UDP 161: SNMP, if not used, better to close it.
Leaving these ports open unnecessarily is one of the most common cybersecurity mistakes . Perform frequent scans on your network to detect these instances. Port management is an ongoing task to secure your network, so you need to know how to address common errors that may arise.
Good practices for opening ports
- Open only the necessary ports: Less is more in terms of security.
- Use local and perimeter firewalls: Configure firewalls on each server and at the edge of the network.
- Change default ports if you can: Especially in RDP, changing port 3389 reduces automated attacks.
- Limit access by IP: Use whitelists to restrict which origins can access your server.
- Audit periodically: Use scanning tools to detect unnecessarily open ports.
Properly managing open ports in Windows Server is essential not only to ensure services function properly, but also to minimize the attack surface. Knowing each role, which ports you need, and how to secure them will help you have a much more robust infrastructure against internal or external threats.
Passionate writer about the world of bytes and technology in general. I love sharing my knowledge through writing, and that's what I'll do on this blog, show you all the most interesting things about gadgets, software, hardware, tech trends, and more. My goal is to help you navigate the digital world in a simple and entertaining way.