Port 3269Microsoft Global Catalog SSL

Port 3269 is used by Microsoft's Global Catalog service operating over SSL/TLS encryption. This port facilitates secure access to a forest-wide directory in Active Directory, enabling encrypted LDAP searches that span multiple domains. Utilizing SSL ensures sensitive directory queries and authentication details remain protected during transmission..

transport
tcp · udp

2 transports registered

in transit
encrypted

payload protected on the wire

assignment
official

registered with iana

risk
4/10

caution

lookups
26,436

rank 61 of 993 · top 6%

Technical Details

what runs on :3269

Microsoft's Global Catalog (GC) is an integral component of Active Directory, providing a searchable forest-wide directory that consolidates information from all domains. Unlike the typical Lightweight Directory Access Protocol (LDAP) port 389 or global catalog port 3268 which are unencrypted by default, port 3269 specifically handles secure LDAP (LDAPS) traffic between clients and the Global Catalog.

The secure nature of port 3269 means that it leverages SSL/TLS to encrypt data exchange, which includes directory queries and potential authentication credentials. This encryption is crucial in enterprise environments handling sensitive identity information and cross-domain trust relationships. When clients connect over port 3269, SSL negotiation ensures data confidentiality and integrity between the client and global catalog server.

Administrators commonly configure domain controllers with the global catalog role to listen on port 3269 for secure queries. This enables safe enumeration of users, groups, and other forest-wide resources without exposing them to the risk of interception or unauthorized access. Port 3269 is thus critical in multi-domain Active Directory forests with high security requirements.

Security Information

exposure of :3269

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

security averages 3.8 across 216 ports — this one sits 0.2 above.

in transit

encrypted

payloads are protected on the wire

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common Vulnerabilities:

  • Exposure of port 3269 can allow attackers to perform enumeration of directory services if authentication is weak or misconfigured
  • Use of outdated SSL/TLS protocols may result in susceptibility to downgrade attacks or protocol-specific vulnerabilities (e.g., POODLE, BEAST)
  • If domain controllers have poorly managed certificates, attackers might exploit man-in-the-middle attacks by impersonating legitimate servers

Common Mitigations:

  • Enforce strong, up-to-date TLS protocols (TLS 1.2/1.3) and disable legacy, insecure versions
  • Implement network segmentation and strict firewall rules to limit access to port 3269 only from trusted sources
  • Require strong authentication methods such as Kerberos and restrict anonymous LDAP binds
  • Use properly issued and managed certificates to safeguard SSL connections and verify server authenticity
  • Monitor and log LDAPS activities for anomalous behaviors indicating potential reconnaissance or attack attempts

the 8 most looked-up other ports in security — 216 ports carry that label.

risk mix of the 8 listed

  • caution100%

3 of 8 encrypted