Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

For ordinary modern Windows file sharing, the key port is TCP 445, used by direct-hosted SMB. Ports 137–139 belong to older NetBIOS-over-TCP/IP services; SMB2 and later do not use them for shares. Keep those legacy ports only when a documented compatibility need requires them.

What port does SMB use?

Direct-hosted SMB uses TCP port 445. SMB 2.0.2 and later use this TCP/IP path rather than NetBIOS transport. Microsoft says Windows Vista and Windows Server 2008 introduced the SMB 2.0.2 path. Removing NetBIOS transport also means file-sharing name resolution uses DNS rather than WINS or NetBIOS broadcasts. See Microsoft’s Direct host Server Message Block (SMB) over TCP/IP.

What are ports 445, 139, 138, and 137 used for?

Port Transport Role When it matters
445 TCP Direct-hosted SMB Normal port for modern Windows SMB file sharing.
139 TCP NetBIOS Session Service Legacy SMB transport over NetBIOS; not used by SMB2-or-later shares.
138 UDP NetBIOS Datagram Service NetBIOS datagram traffic, not the TCP session used by direct-hosted SMB.
137 UDP; Microsoft also lists TCP NetBIOS Name Service (NBName) Traditional NetBIOS name service, relevant only when a legacy dependency needs it.

Microsoft lists the traditional NetBIOS-over-TCP/IP services as NBName on UDP and TCP 137, NBDatagram on UDP 138, and NBSession on TCP 139. For common firewall mapping, UDP 137 is the relevant NetBIOS name-resolution port. The four numbers are therefore not four interchangeable SMB file-data ports.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do I need ports 137, 138, and 139 for file sharing?

Usually not for a modern SMB2-or-later Windows share. Microsoft’s security guidance says SMB2-or-later shares do not use NetBIOS ports 137–139. They may still be needed if a deployment has a specific legacy SMB1 compatibility requirement or another application or device depends on NetBIOS.

Before creating broad allow rules, check the SMB dialects in use, endpoint Windows versions, name-resolution method, and whether a particular legacy client or server actually requires NetBIOS. Opening all four ports will not by itself fix a share-access problem: permissions, DNS or other name resolution, firewall scope, and server configuration can also prevent access. See Secure SMB Traffic in Windows Server.

Should port 445 be open to the internet?

Microsoft recommends blocking inbound TCP 445 from the internet at the corporate hardware firewall, and also blocking outbound TCP 445 to the internet. Its guidance says outbound internet SMB is unlikely to be needed, aside from some public cloud offerings. For internal connections, use narrowly scoped rules that permit only the systems that need SMB; inventory existing shares and usage before disabling SMB server functionality.

Opening a port is not the whole security story. Microsoft says inbound and outbound SMB connections are required to be signed by default starting with Windows 11 version 24H2 and Windows Server 2025. Guest logons lack standard protections such as signing and encryption. See Microsoft’s SMB security hardening in Windows Server and Windows Client.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why Windows firewall defaults depend on the release

Beginning with Windows 11 version 24H2 and Windows Server 2025, built-in Windows firewall rules for SMB no longer include inbound NetBIOS ports 137–139. Microsoft explains that SMB2-or-later shares do not use those ports; administrators who still need SMB1 must manually configure the required firewall rules. Older Windows releases may have different defaults, so do not apply a legacy firewall checklist to every version. Microsoft’s SMB features in Windows and Windows Server documents this change.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Advanced exception: alternative SMB ports

In newer configurations, the port can differ from the ordinary TCP 445 setup. Microsoft documents an alternative-port feature for SMB dialect 3.1.1 on Windows Server 2025 and Windows 11, with standard ports identified as TCP 445, QUIC 443, and RDMA 5445. This is a version-specific option; it does not change the basic answer for ordinary direct-hosted SMB.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.