windows file sharing

When dealing with windows file sharing, I've noticed it tries 135 and 137.  If those are not open it tries 445.

Am I correct to assume if I open just 445, I won't need to open 135 and 137?
trojan81Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

mcsweenSr. Network AdministratorCommented:
you need TCP 139, 445 and UDP 137, 138.  SMB happens on 445 but you also need NetBIOS over TCP/IP which the other 3 ports cover.
0
McKnifeCommented:
Incorrect. Your own assumption is indeed correct, only 445.
0
McKnifeCommented:
And 135 is something different, it's rpc.
0
Increase Security & Decrease Risk with NSPM Tools

Analyst firm, Enterprise Management Associates (EMA) reveals significant benefits to enterprises when using Network Security Policy Management (NSPM) solutions, while organizations without, experienced issues including non standard security policies and failed cloud migrations

Natty GregIn Theory (IT)Commented:
What Mcknife said, you definitely don not want 135 n 137 open
0
trojan81Author Commented:
So officially which is the port?  I know 445 works. Why does Microsoft talk about other ports?  
It seems to me it tries other netbios over tcp first and then if that doesnt work, it tries 445.
0
mcsweenSr. Network AdministratorCommented:
NetBIOS over TCP/IP is for name resolution.  If you only want to open TCP 445 you must:

1. Access the shares by IP address only (\\192.168.1.100\sharename)
OR
2. Setup DNS to resolve names on the LAN
OR
3. Add IP/hostname mappings to your hosts file on each computer

Just out of curiosity where does this firewall reside that you are opening ports on?
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
McKnifeCommented:
That is it, exactly.
Microsoft would surely "promote" to only open port 445 if there weren't people who don't know about name resolution. That said: if you have DNS running like on a domain or, if no DNS is at hand, if you feel able to edit the host file, or, if you feel comfortable with using IPs, of course you should use and open only 445.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Hardware Firewalls

From novice to tech pro — start learning today.