This is solely a web server so should be ports for HTTPS. There should not be any traffic leaving the server on 389 externally and its LDAP traffic so definitely a concern. Port 389 can be disabled. Not to mention LDAPS would be 636 not 637. http://ports.my-addr.com/tcp_port-udp_port-application-and-description.php?port=637