How to block TCP port 445 in Windows (2024)

View the security misconfiguration catalog

  • Misconfiguration Name
  • Inbound connection in port 445 (TCP) is not blocked in Windows firewall
  • Description
  • Port 445 should not be exposed to the internet as it arises secrious security concern. Blocking TCP 445 will prevent file and printer sharing, thereby preventing Wannacry ransomware from spreading across your network
  • Severity
  • Moderate
  • Category
  • Windows Firewall
  • Resolution
  • Follow the below steps to resolve the misconfiguration.Step 1: Open the Control PanelStep 2: Click on Windows Firewall/ Windows Defender firewallStep 3: Navigate to advanced settings.Step 4:Right click on inbound rules and click on new rule.Step 6:Select port and press nextStep 7:Specify the port 445 under specific local ports, select TCP and press next.Step 8:click on block the connection and click next.Step 9:Select Domain, Private and Public and click next.Step 10:Give a name and description and click finish.
  • Potential issues that may arise after applying the resolution
  • Altering the existing security setting may create the following impact in your network operations. Blocking TCP 445 will prevent file and printer sharing and also other services such as DHCP (dynamic host configuration protocol) which is frequently used for automatically obtaining an IP address from the DHCP servers used by many corporations and ISPs(Internet Service Providers) will stop functioning.
  • Does remediation require reboot?
  • No

Vulnerability Manager Plus tracks security configurations and remediate misconfigurations in your network systems from a centralized console. View a list of all the security misconfigurations detected by Vulnerability Manager Plus.

How to block TCP port 445 in Windows (2024)

FAQs

How to block TCP port 445 in Windows? ›

Step 1: Open the Control Panel Step 2: Click on Windows Firewall/ Windows Defender firewall Step 3: Navigate to advanced settings. Step 4:Right click on inbound rules and click on new rule. Step 6:Select port and press next Step 7:Specify the port 445 under specific local ports, select TCP and press next.

How do I block unneeded TCP 445 connections? ›

How to Close Port 445 in Windows 11, 10, 7
  1. Go Start > Control Panel > Windows Firewall and find Advanced settings on the left side.
  2. Click Inbound Rules > New rule. ...
  3. Choose Block the connection > Next. ...
  4. Check if you have created the rule by Properties > Protocols and Ports > Local Port.
Apr 6, 2023

Is it OK to block port 445? ›

The best approach is to explicitly block all inbound access to TCP 445 at the top of the rule base to avoid mistakenly opening it up by lower rules. We also recommend blocking port 445 on internal firewalls to segment your network and prevent lateral movement – this will prevent internal spreading of the ransomware.

How do I check my port 445 on Windows? ›

Answer: Open the Run command and type cmd to open the command prompt. Type: “netstat –na” and hit enter. Find port 445 under the Local Address and check the State. If it says Listening, your port is open.

How do I unblock port 445 in Windows 10? ›

Right click Inbound Rules and select New Rule. Add the port you need to open and click Next. Add the protocol (TCP or UDP) and the port number into the next window and click Next. Select Allow the connection in the next window and hit Next.

How do I stop port 445 from listening? ›

How to Block Port 445 in Windows Firewall
  1. Go Start > Control Panel > Windows Firewall and find Advanced settings on the left side.
  2. Click Inbound Rules > New rule. ...
  3. Choose Block the connection > Next. ...
  4. Check if you have created the rule by Properties > Protocols and Ports > Local Port.
Apr 6, 2023

What is port 445 used for in Windows? ›

Port 445 is a traditional Microsoft networking port with tie-ins to the original NetBIOS service found in earlier versions of Windows OSes. Today, port 445 is used by Microsoft Directory Services for Active Directory (AD) and for the Server Message Block (SMB) protocol over TCP/IP.

What runs over port 445? ›

Port 445 is a traditional Microsoft networking port with tie-ins to the original NetBIOS service found in earlier versions of Windows OSes. Today, port 445 is used by Microsoft Directory Services for Active Directory (AD) and for the Server Message Block (SMB) protocol over TCP/IP.

What malware is using port 445? ›

It's typically used for file sharing, but Port 445 is now infamous for its role in the WannaCry ransomware epidemic. The port is often left open to allow computers to communicate with printers, and hackers took advantage of it, which is how ransomware spread in this particular case.

How do I check if my port 445 is open? ›

Answer: Open the Run command and type cmd to open the command prompt. Type: “netstat –na” and hit enter. Find port 445 under the Local Address and check the State. If it says Listening, your port is open.

How do I stop TCP ports from listening? ›

The fuser command combined with the -k (kill) option will end all associated processes that are listening on a TCP or UDP port. Simply provide the port number and type (TCP or UDP) in the fuser command. You can use the lsof command to verify that processes are no longer running on the target port.

How do I block unwanted ports? ›

Block port in Firewall
  1. To see the list of rules, select "Inbound Rules" from the menu that appears on the left side of the window. ...
  2. Select port and then press the next button.
  3. Click on "Specific local ports" and choose a port number (e.g., 80). ...
  4. Choose Block the Connection and then click Next.
Jan 17, 2023

How do you stop a TCP connection? ›

The common way of terminating a TCP connection is by using the TCP header's FIN flag. This mechanism allows each host to release its own side of the connection individually. Suppose that the client application decides it wants to close the connection. (Note that the server could also choose to close the connection).

How do I block unused ports and services? ›

There are a few ways to do this:
  1. Network Firewall Rules. Using your network firewall, remove all rules that allow inbound network access. ...
  2. Disable UPNP on Firewall. Many consumer firewalls come with a feature called UPNP enabled. ...
  3. Enable Host-Based Firewall.
Dec 8, 2022

Top Articles
Latest Posts
Article information

Author: Merrill Bechtelar CPA

Last Updated:

Views: 5469

Rating: 5 / 5 (50 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Merrill Bechtelar CPA

Birthday: 1996-05-19

Address: Apt. 114 873 White Lodge, Libbyfurt, CA 93006

Phone: +5983010455207

Job: Legacy Representative

Hobby: Blacksmithing, Urban exploration, Sudoku, Slacklining, Creative writing, Community, Letterboxing

Introduction: My name is Merrill Bechtelar CPA, I am a clean, agreeable, glorious, magnificent, witty, enchanting, comfortable person who loves writing and wants to share my knowledge and understanding with you.