Port 135: MS-RPC

Port 135 is the Microsoft RPC endpoint mapper. Windows services use it to negotiate dynamic ports, which is why it is a frequent firewall and hardening target.

TCPWindowsUnencrypted by defaultIANA assigned
Port number135
ServiceMicrosoft RPC endpoint mapper
ProtocolTCP
CategoryWindows
Default encryptionNo
Security note. Port 135 is not encrypted by default. Restrict it to trusted networks, or use an encrypted alternative where one exists, to avoid exposing credentials and data in transit.

Frequently asked questions

What is port 135 used for?

Port 135 is the Microsoft RPC endpoint mapper. Windows services use it to negotiate dynamic ports, which is why it is a frequent firewall and hardening target.

Is port 135 TCP or UDP?

Port 135 (MS-RPC) uses TCP.

Is port 135 secure?

Port 135 is not encrypted by default. Where possible, use an encrypted alternative or tunnel it over TLS or a VPN.

Should I open port 135 on my firewall?

Only if you specifically need MS-RPC. Expose it to the smallest set of trusted sources, and never open database or Windows-service ports to the whole internet.