Port 445 carries Server Message Block: file shares, printer shares, remote administration and domain member traffic. It is essential inside a network and must never be reachable from the internet. Internally it belongs between workstations and servers, not between workstations.
- It carries authentication and remote execution, not just files
- Blocking it to domain controllers breaks logon, not file sharing
- Never open it to the internet, inbound or outbound
- Ports 137 to 139 are the older path to the same protocol
- SMBv1 is the version the wormable attacks targeted
On this page
What uses itWhat actually runs on port 445
SMB is older and broader than its reputation as the file sharing port suggests. Four kinds of communication use it, and only the first is what people picture.
File shares. Mapped drives, UNC paths and everything reached as \\server\share. This is the visible use.
Printer shares. A printer published from a Windows server is reached the same way, over the same port.
Named pipes, which carry remote administration. A great deal of Windows remote management runs over SMB rather than over a protocol of its own. Remote service control, remote registry access, and many management tools reach systems through named pipes on port 445.
Domain member traffic. A machine joined to a domain fetches group policy from a share on the domain controller, and roaming profiles and logon scripts arrive the same way. This is why blocking port 445 between workstations and domain controllers breaks logon rather than breaking file sharing.
That third and fourth item are why the port matters more than a file sharing port would. It is a channel for authentication and remote execution, not just for documents, and that is the whole security question.
The older ports445 and 139, and the difference between them
Two sets of ports carry SMB, from two eras, and both often appear in a scan.
Ports 137, 138 and 139 are the NetBIOS ports. In the original design, SMB ran on top of NetBIOS, which needed a name service on UDP 137, a datagram service on UDP 138, and a session service on TCP 139. SMB communication rode inside that.
Port 445 is SMB directly over TCP. Windows 2000 introduced it, cutting NetBIOS out of the path entirely. Everything modern uses this.
The older ports still appear because equipment and software keep supporting them. They should be closed, both at the perimeter and, wherever possible, on internal networks. Anything still requiring NetBIOS for name resolution is old enough that finding out what it is is worth the hour.
| Port | Protocol | Purpose | Should it be open |
|---|---|---|---|
| 445 | TCP | SMB directly over TCP | Internally, to the machines that need it |
| 139 | TCP | SMB over NetBIOS session service | No, unless something legacy demands it |
| 138 | UDP | NetBIOS datagram service | No |
| 137 | UDP | NetBIOS name service | No |
Why it is targetedWhy this is the port on every hardening list
Three properties combine to make SMB port 445 the one that appears in security incident reports.
It is everywhere. Every Windows system has it. A network of any size has hundreds of listeners, and finding one takes seconds.
It carries credentials. SMB authenticates, so an attacker with access to it can attempt credentials against it, replay them, or relay them to a third system. Passing stolen credentials from one machine to another over SMB is how a single compromise becomes a network wide one.
It has a history of wormable vulnerabilities. The most consequential ransomware attacks of the last decade spread through vulnerabilities in SMB, using an exploit that needed nothing from a user: no attachment, no click, just an unpatched system reachable on port 445. Once inside a flat network, the attack spread by itself.
That last property is the one that produced the absolute rule about internet exposure. An SMB service open to the internet is not a risk to weigh, it is a system that will be found by an automated scan and attacked, usually within hours.
The policyWhat to actually do about it
The advice splits cleanly into the perimeter, where the answer is simple, and the interior, where it takes thought.
| Where | Verdict | What it costs you |
|---|---|---|
| Inbound from the internet, 445 and 137 to 139 | Deny, always | Nothing. Use a VPN instead |
| Outbound to the internet, 445 | Deny | Nothing legitimate connects out on it |
| Workstation to server and domain controller | Allow | Required for drives, policy and logon |
| Workstation to workstation | Deny | Nothing, and it removes the lateral path |
| SMBv1, anywhere | Disable | Whatever still needs it, which is the real project |
| SMB signing | Require | A little throughput, and it stops relay attacks |
Block 445 and 137 to 139 inbound at the perimeter. All of them, always. There is no legitimate reason to leave these SMB ports open to the internet, and every remote access requirement they might satisfy is better satisfied by a VPN.
Block 445 outbound too. This is the security rule people forget. A system that connects outward on 445 is either being tricked into sending credentials to somebody else's server, or exfiltrating, and legitimate software does not do it. Blocking it outbound also stops a whole class of attacks that begin with a link to a remote share.
Disable SMBv1 everywhere. It is the version the wormable attacks targeted, it has no encryption and weak authentication, and it has been removed by default from current Windows systems. If something still needs it, the correct project is replacing that thing.
Require SMB signing. It prevents the relay attacks in which an attacker forwards an authentication attempt to a different server, and it is one of the cheapest security controls available here. It is on by default for domain controller traffic and worth enforcing more widely.
Segment internal networks. Workstations need access to port 445 on servers and domain controllers. They almost never need it to each other. A firewall rule or a VLAN boundary that stops workstation to workstation SMB removes the path a ransomware attack uses to spread, and breaks nothing anyone does deliberately.
Turn on SMB encryption where it matters. SMB 3 can secure the session with encryption. It costs some throughput and it protects file communication crossing links you do not fully control.
Know what your shares are. Shares accumulate, access permissions drift, and an "Everyone" share created for a project in 2019 is still there. The share list is worth auditing on its own schedule.
PitfallsWhere people go wrong
Opening 445 through a firewall for remote work. It happens, usually to give somebody access to a file server from home. Every scanner on the internet finds it. Secure remote access goes through a VPN, without exception.
Blocking inbound and leaving outbound open. The outbound rule stops credential theft to external systems, and it is the half of the security policy that gets skipped.
Leaving SMBv1 enabled because something needs it. Something usually does, and it is usually a scanner or an old appliance. The right answer is to replace or isolate that system rather than keep a vulnerable protocol version alive across the network.
Allowing SMB between workstations. It is the path lateral movement uses. Machines that share nothing with each other have no reason to speak SMB to each other.
Assuming a VPN makes it secure. A VPN limits who has access, which is worth a great deal. It does nothing about a compromised laptop connected to that VPN.
Confusing port 445 with a file sharing problem. Blocking it internally without thinking breaks group policy, logon scripts and domain membership, because SMB carries those too.
Forgetting the ports underneath. Closing 445 and leaving 139 open leaves the same protocol open by an older path, with all of the same risks.
ComparisonThree ways to reach a file server from outside, and what each survives
| Criterion | SMB on 445, exposed | SMB over a VPN | A file sync service |
|---|---|---|---|
| Reachable from the internet | Yes, and that is the problem | No | Yes, by design |
| Works with mapped drives | Yes | Yes | Partly |
| Survives a scanning bot finding it | No | Yes | Yes |
| Depends on the endpoint being trusted | Yes | Yes | Yes |
| Carries domain authentication | Yes | Yes | No |
| Appropriate for remote workers | No | Yes | Yes |
The first and third rows are the whole argument. Every other property of SMB is fine, and the security risks people list are almost all downstream of one decision. The one thing it cannot survive is being open to anybody who wants to try.
FAQFrequently asked questions
What is port 445 used for?
Server Message Block: Windows file shares, printer shares, remote administration over named pipes, and the traffic between a domain member and a domain controller.
Is SMB port 445 dangerous?
Internally it is necessary. Open to the internet it is one of the most attacked ports there is, because it is everywhere, it carries credentials, and it has a history of wormable vulnerabilities.
Should I block port 445?
Inbound from the internet, always. Outbound to the internet, yes. Internally, restrict it so that workstations reach servers and not each other.
What is the difference between port 445 and port 139?
Port 139 carries SMB over the older NetBIOS session service. Port 445 carries SMB directly over TCP and is what everything modern uses. Both should be closed at the perimeter.
What breaks if I block port 445 internally?
Mapped drives, printer shares, group policy delivery, logon scripts and roaming profiles. Block it between workstations rather than between workstations and servers.
What is SMBv1 and why disable it?
The original version of the protocol. It lacks encryption, has weak authentication, and was the target of the wormable exploits behind the largest ransomware events of the last decade. Current Windows versions do not install it by default.
How do I check whether port 445 is open to the internet?
Scan your public addresses from outside, or use an external port checking service. Do not rely on the firewall configuration alone, because the mistake is usually a rule somebody added and forgot.
What is SMB signing?
A signature on each message that proves it came from the party that authenticated. It defeats relay attacks, where an attacker forwards your authentication to a different server.
Can SMB traffic be encrypted?
Yes, from SMB 3 onward, per share or per server. It costs some throughput and is worth enabling for anything crossing a link you do not control.
Why do attacks target this port specifically?
Because it is present on every Windows system, it authenticates, and it can be used to run things remotely. It is the shortest path from one compromised machine to the rest of the network.
Is blocking outbound 445 really necessary?
Yes. A machine tricked into connecting to an external SMB server can leak credentials in the attempt. No legitimate business software connects outward on this port.
How does a ransomware attack use port 445?
Once inside, it looks for other systems listening on 445 and either exploits an unpatched vulnerability or uses stolen credentials for access. In a flat network with no internal filtering, that is a fast and complete spread.
What should remote workers use instead?
A VPN to reach the file server the way they would in the office, or a file service designed to be internet facing. Publishing the port directly is not one of the options.
What does SMB stand for?
SMB stands for Server Message Block. The SMB meaning in networking is the protocol Windows uses to share files and printers, which runs directly over TCP port 445. In business writing the same letters mean small and midsize business, which is unrelated.
What are the basics of SMB security?
SMB security comes down to four things: never expose port 445 to the internet, disable SMB version 1, require SMB signing, and turn on SMB encryption for sensitive shares. Blocking port 445 between workstations also stops most ransomware from spreading sideways.
Keep readingRelated concepts
Read next · Network security What Is a Firewall? The inbound and outbound rules for this port are the clearest example of a policy worth writing down. Open this next14 min- Directory and identity · 15 min Active Directory Explained Group policy, logon scripts and roaming profiles all arrive over SMB, which is why blocking it to a domain controller breaks logon.
- Switching · 14 min What Is a VLAN? Stopping workstation to workstation SMB is a segmentation decision before it is a firewall rule.
- Ports · 10 min Port 135, the Endpoint Mapper, and the Ports It Points At The neighboring port, and the worm that made it famous.
- Ports · 8 min Port 4444, and Why an Abandoned Port Makes a Clean Signal The port with no baseline to compare against.
- Shared storage · 9 min NFS vs SMB, and Why the Clients Decide How SMB compares with NFS, why CIFS is just an old dialect, and why SMB1 should be off.
- Ports · 10 min Port 1433, and Why SQL Server Is Rarely Only on 1433 The database port on the same servers, and why a single number rarely describes it.