CIFS protocols and firewall ports

For the CIFS service to work properly in an Active Directory (AD) domain environment, the following protocols and firewall ports need be allowed or opened to enable the CIFS server to communicate smoothly with Active Directory Domain Controllers and Windows/CIFS clients.

Internet Control Message Protocol (ICMP) protocol must be allowed through the firewall from the CIFS server to the domain controllers. Enable "Allow incoming echo request" is required for running the CIFS service.

Table: Additional CIFS ports and protocols lists additional CIFS ports and protocols.

Table: Additional CIFS ports and protocols

Port

Protocol

Purpose

53

TCP, UDP

DNS

88

TCP, UDP

Kerberos

139

TCP

DFSN, NetBIOS Session Service, NetLog

445

TCP, UDP

SMB, CIFS, SMB2, DFSN, LSARPC, NbtSS, NetLogonR, SamR, SrvSvc

464

TCP, UDP

Kerberos change or set a password

3268

TCP

LDAP GC

4379

TCP

CTDB in CIFS

Table: LDAP with SSL ports lists the ports that are required for LDAP with SSL.

Table: LDAP with SSL ports

Port

Protocol

Purpose

636

TCP

LDAP SSL

3269

TCP

LDAP GC SSL