Skip to main content

Active Directory Ports

Review a full list of protocols and ports required for monitoring Active Directory.

  • Allow outbound connections from the dynamic (1024 - 65535) local port on the computer where Netwrix Auditor Server resides.
  • Allow outbound connections to remote ports on the source and inbound connections to local ports on the target.

Tip for reading the table: For example, on the computer where Netwrix Auditor Server resides (source), allow outbound connections to remote 389 TCP port. On domain controllers in your domain (target), allow inbound connections to the local 389 TCP port.

PortProtocolSourceTargetPurpose
389TCP\UDPNetwrix Auditor ServerDomain controllersLDAP Common queries
3268TCPNetwrix Auditor ServerDomain controllersLDAP Group membership GC search
3269TCPNetwrix Auditor ServerDomain controllersGlobal catalog LDAP over SSL
88TCP/UDPNetwrix Auditor ServerDomain controllersKerberos authentication
135 and dynamic range: 1024 -65535TCPNetwrix Auditor ServerDomain controllersWindows Management Instrumentation. gpupdate /force
445TCPNetwrix Auditor ServerDomain controllersSMB 2.0/3.0 Authenticated communication between Netwrix Auditor Server and domain controllers.
53UDPNetwrix Auditor ServerDNS ServerDNS Client

* - for Exchange 2010 only