Skip to main content
NetApp Knowledge Base

Which ports need to be open for CIFS between ONTAP systems and Domain Controllers?

Last Updated:

Applies to

  • ONTAP 9
  • Data ONTAP 8


For a proper communication between ONTAP systems and Windows Domain Controllers the following ports must be open on the firewall

ONTAP System Direction Domain Controller
ANY  ->

SMB over IP (TCP:445)

DNS (TCP and UDP: 53)

LDAP (TCP: 389)

LDAPS (TCP: 636) (optional: only if LDAPS enabled)

Kerberos (TCP and UDP: 88)

Kpasswd (TCP and UDP: 464)

SMB over IP (TCP:445) (optional: needed to access the shares)

<- ANY

Additional Information

ONTAP can use any IP on the SVM for outgoing traffic, the choice of which interface will be used is based on routing to the destination and not which protocol has been enabled on the interface itself.


NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.