The default port for LDAP is port 389, but LDAPS uses port 636 and establishes SSL/TLS upon connecting with a client.

Port Number: 636; TCP / UDP: TCP; Protocol / Name: ldaps; Port Description: LDAP using TLS/SSL (was sldap)


Disabling LDAP access on port 389 will effect on AD communication and lead to AD issue.

You should use TCP ports 389 and/or 636. . 389 and 636 are simply standards-based defaults.


Sessions that use TLS/SSL by using a predetermined port (636, 3269, or a custom LDS port), or standard ports (389, 3268, or a custom LDS port) that use the STARTTLS extended operation.

Set your Base DN to the top of your AD forest to capture users in all domains below.

RootDSE information should print in the right pane, indicating a successful connection.

It is also used as the basis for Microsoft's Active Directory.

1 and ::1 local interface addresses Note: - In RHEL 7 and 8, 389 port is used for replication instead of 7389 port.

Port 636 & 3269 are listing after promoting a DC. The data transfer is signed and encrypted. .

Outgoing TCP Port 389 - LDAP Authentication (may also use 636 for LDAPS) Outgoing TCP Port 443 - Plugin updates. Sessions on ports 389 or 3268 or on custom LDS ports that don't use TLS/SSL for a Simple Authentication and Security Layer (SASL) bind.

The option to use SSL is enabled by default.

0, which supposedly means that it cannot be accessed from outside.

Port 636 is used for the secure version of LDAP (Lightweight Directory Access Protocol) communication, which is called LDAPS.


Inbound ports: IP address Protocol Port DR Vault.

Port 3268 is used for the Global Catalog and port 3269 is used for the Global Catalog with SSL.