Networking · Concept · 10 min read

Port 135, the Endpoint Mapper, and the Ports It Points At

This is the only common Windows port that is a directory rather than a service, which is why a firewall rule that permits it and nothing else fails in a way nobody expects.

Written by Marko Ristic, Editor Updated Sep 8, 2026
2Firewall rules every RPC path needs, which is the whole trap
16384Ports in the default dynamic range, which is not a rule
2003The year Blaster made this port notorious
0Legitimate reasons for workstations to reach each other on it
Short answer

Port 135 is the Microsoft RPC endpoint mapper: it tells a client which dynamic port a service is actually listening on. The real connection then goes to that port, so every RPC firewall rule needs two entries. It should never be open to the internet.

  • A directory, not a service. It answers which port, then steps aside
  • Every RPC conversation needs 135 plus a dynamic high port
  • The dynamic range is 49152 to 65535 on modern Windows
  • Blaster spread on this port in 2003, with no user interaction
  • Blocking it workstation to workstation breaks nothing worth keeping
On this page

The lookupWhat the endpoint mapper actually does

The design is a directory service for ports, and it exists because Windows RPC services do not have fixed TCP port numbers of their own.

A service starts and claims a port. When one of the RPC services on a Windows system starts, it takes an available port from the dynamic range and tells the endpoint mapper: this interface is on this port.

A client asks port 135 where to go. The client connects to TCP 135 on the server system, names the interface it wants by its identifier, and receives a port number.

The client opens a second connection. The real work happens on that second port, not on 135. Port 135 is out of the conversation after the lookup.

The consequence that matters for firewall rules is immediate. Leaving only port 135 open produces a client that successfully learns where the service is and then cannot reach it. Every RPC firewall rule is therefore two rules: port 135, plus the dynamic range, unless the service in question has been pinned to a fixed port.

What is registeredSeeing what is registered

The endpoint mapper will tell you what it knows, which turns a guess about firewall rules into a fact.

PortQry queries the endpoint mapper directly and lists every registered interface with the port it is on. Run against a server it produces the exact list a firewall rule has to accommodate, and against an unreachable server it distinguishes a filtered port from a closed one.

Rpcdump does the same job from the Windows resource kits and produces a longer, noisier list of the same information.

netstat on the server itself shows which process is listening where. Matching the dynamic port from the endpoint mapper to a process identifier confirms which service you are about to open a firewall for, rather than assuming.

Doing this before writing the rule is the difference between permitting one port and permitting sixteen thousand.

The dynamic rangeThe dynamic range, and how to pin it

The default dynamic range on Windows Server 2008 and later is 49152 to 65535, which is 16,384 TCP ports. Older Windows systems used 1024 to 5000, and the change caught a lot of firewall rules by surprise when it happened.

Leaving sixteen thousand ports open through a firewall is not a security control, it is an attack surface. Two better options exist.

Narrow the range. Windows lets you restrict the dynamic range to a smaller block, which turns a sixteen thousand port rule into a few hundred. It is configured on every server system involved and the ranges have to match.

Pin the service to a fixed port. Several important Windows services can be told to use one TCP port permanently, which turns the rule into port 135 plus that one port. This is the standard approach for Active Directory replication across a firewall, and it is worth the effort every time.

There is a third option that people reach for and should not: leaving the whole high range open from anywhere. It permits access to far more than RPC, because that range is also where the source port of every outbound connection lives.

The reputationWhy this port has such a bad reputation

Port 135 has been involved in enough vulnerabilities and incidents that closing it at the perimeter is not a judgment call.

Blaster, in 2003. A buffer overflow vulnerability in the DCOM RPC interface, reachable on an open port 135, was exploited by a worm that needed no user interaction at all. It spread to millions of Windows systems in days, and it is the reason a generation of administrators blocks this port reflexively.

Reconnaissance. The endpoint mapper is a directory, and a directory answers questions. Attackers who gain access to port 135 can enumerate the RPC services a system offers, which is a detailed description of what that system does and where its vulnerabilities might be.

Lateral movement. After a foothold, RPC is how a great deal of Windows remote administration happens: WMI queries, service control, scheduled task creation, remote registry. An internal network with port 135 open between every workstation lets attackers reach all the other systems the way an administrator would, using the tools that are already there.

That last point is the one that matters most today, because the perimeter is usually already handled and the internal network usually is not.

What to permitWhat to permit, and where

The useful rule is not to close port 135 everywhere, because that breaks Windows management. It is to permit access narrowly.

PathPort 135Why
Internet to anythingBlockedNo legitimate case exists
Workstation to workstationBlockedThis is how lateral movement travels
Management systems to serversPermittedMonitoring, WMI, remote administration
Domain controller to domain controllerPermittedReplication and directory operations
Server to domain controllerPermittedDomain membership and Kerberos adjacent work
Site to site over a VPNPermitted, narrowedPin the service to a fixed port first

Blocking workstation-to-workstation RPC is the single highest-value security change on this list, and it breaks almost nothing, because workstations have no legitimate reason to remotely manage each other.

What breaksWhen it is blocked, and what breaks

Recognizing the symptom saves an afternoon.

WMI queries and remote management fail. Monitoring tools, inventory agents and remote administration consoles all use RPC services, and they fail with an RPC server unavailable message that names nothing useful.

Some Active Directory operations hang. Replication, trust operations and certain administrative tools use RPC services on top of the endpoint mapper. DNS and Kerberos still work, so the domain looks healthy while specific tasks do not.

Printing stops working across a boundary. Print spooler operations use RPC, and print servers across a firewall are a classic case of this.

The client can look up and then cannot connect. Port 135 is permitted and the dynamic range is not. This is the specific failure to suspect whenever the lookup itself is clearly succeeding.

PitfallsWhere people go wrong

Permitting port 135 and expecting RPC to work. The lookup succeeds and the second connection is refused. Two rules are needed, always.

Leaving the whole dynamic range open through a firewall. Sixteen thousand open ports is not a rule, it is an attack surface. Narrow the range or pin the service.

Blocking port 135 everywhere and then chasing the fallout. Management tools, monitoring and parts of the directory need it. Permit it from the systems that do the managing, and block it between the systems that do not.

Assuming the system is secure because the perimeter blocks it. The interesting security risk today is internal. A flat network with it open everywhere gives attackers the same reach an administrator has.

Confusing it with SMB on 445. They are different protocols with different uses and they are both blocked at the perimeter for different reasons. RPC discovers services; SMB moves files and named pipes.

Treating an RPC server unavailable error as a server problem. More often it is a firewall between the two machines, or the dynamic range being unreachable.

A LOOKUP ON 135, THEN A CONNECTION SOMEWHERE ELSE ENTIRELYCLIENTWants a serviceWINDOWS SERVERRuns RPC servicesFW1. Which port is that service on?TCP 1352. It is on port 52341the endpoint mapper answers3. All the actual work happens hereTCP 52341, from the dynamic rangeSO THE FIREWALL NEEDS TWO RULES: PORT 135, PLUS THE DYNAMIC RANGE OR ONE PINNED PORTPermit only 135 and the client looks the service up, then cannot reach it. That is the whole failure.
The green leg is the one firewall rules forget. Everything on this page follows from the fact that port 135 is not where the work happens.

ComparisonFour Windows ports, and the one that needs a second rule

Criterion135 RPC445 SMB389 LDAP88 Kerberos
What it is forFinding servicesFile and pipe accessDirectory queriesAuthentication
Needs a second portYes, dynamicNoNoNo
Safe from the internetNeverNeverNeverNever
Needed workstation to workstationNoNoNoNo
Needed to a domain controllerYesYes, for policyYesYes
Famous wormBlaster, 2003WannaCry, 2017NoneNone

The second row is what makes this port different from every other one on the list. Everything else here is one port and one rule, and RPC is a lookup followed by a connection somewhere else entirely.

FAQFrequently asked questions

What is port 135 used for?

The Microsoft RPC endpoint mapper. Clients connect to it to find out which dynamic TCP port an RPC service on that system is listening on, then connect to that port.

Is port 135 TCP or UDP?

Both are registered and TCP is what nearly everything uses. Firewall rules should account for both when locking it down.

Should I block port 135?

From the internet, always: an open port 135 is a security exposure with no legitimate use. Between workstations, yes, and it breaks nothing. From management systems to servers, no, because that is what Windows remote administration runs on.

Why does RPC need a second port?

Because RPC services claim a port from a dynamic range at startup rather than using a fixed one. Port 135 exists to tell clients which port that turned out to be.

What is the RPC dynamic port range?

49152 to 65535 on Windows Server 2008 and later. Older versions used 1024 to 5000, which is why old firewall rules stopped working after an upgrade.

Can I narrow the dynamic range?

Yes, and you should when RPC has to cross a firewall. Configure the same restricted range on every server involved, then permit that block rather than sixteen thousand ports.

Can a service use a fixed port instead?

Several can, including Active Directory replication. Pinning the service turns the firewall rule into port 135 plus one known port, which is the right answer whenever it is available.

What was the Blaster worm?

A 2003 worm that exploited a DCOM RPC vulnerability reachable on port 135, spreading with no user interaction to millions of Windows systems. It is why this port is blocked reflexively.

What breaks if I block it?

WMI and monitoring, remote administration tools, some Active Directory operations, and printing across the boundary. All of them fail with RPC server unavailable.

What does RPC server unavailable mean?

Usually that port 135 or the dynamic port is unreachable, rather than that the server is down. Check the firewall between the two machines before checking the server.

Is port 135 the same as DCOM?

DCOM is built on RPC and uses the endpoint mapper on port 135 to find its interfaces. They are closely related and not the same thing.

Do I need port 135 for a domain to work?

Some parts of it, yes. Logon uses Kerberos, DNS and LDAP, but replication, trusts and several administrative operations use RPC.

Why is internal blocking more important than perimeter blocking now?

Because almost every perimeter already blocks it, and almost no internal network does. Lateral movement between workstations is the risk that actually remains.

Read next · Ports What Is a Port Number? Where the dynamic range comes from, and why services take a port from it rather than owning one. Open this next12 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.