We will look at what this port is used for, and how it relates to the security in Windows 2000.
SMB over TCP vs SMB over NBT The SMB (Server Message Block) protocol is used among other things
for file sharing in Windows NT / 2000.

In Windows NT it ran on top of NBT (NetBIOS over TCP/IP), which used the famous ports 137, 138 (UDP)
and 139 (TCP). In Windows 2000, Microsoft added the possibility to run SMB directly over TCP/IP,
without the extra layer of NBT. For this they use TCP port 445.

When Windows 2000 uses port 445, and when it uses 139 In Windows 2000 you have the possibility to
disable NetBIOS over TCP/IP.

1. You do this by right-clicking on My Network Places and selecting Properties.
2.  Then right-click on the appropriate Local Area Connection icon, and select Properties.
3. Next, click on Internet Protocol (TCP/IP) and Properties.
4. Now click Advanced, and select the WINS tab. There you can enable or disable NetBIOS over TCP/IP.

The changes take effect immediately without rebooting the system. From now on I will refer to the “client“
as the computer from where you map drives and other shared resources, and to the “server” as the
computer with resources that are shared. I will also refer to NetBIOS over TCP/IP only as NBT.
If the client has NBT enabled, it will always try to connect to the server at both port 139 and 445
simultaneously.

If there is a response from port 445, it sends a RST to port 139, and continues it’s SMB session to
port 445 only. If there is no response from port 445, it will continue it’s SMB session to port 139 only,
if it gets a response from there.If there is no response from either of the ports,
the session will fail completely.

If the client has NBT disabled, it will always try to connect to the server at port 445 only.
If the server answers on port 445, the session will be established and continue on that port.
If it doesn’t answer, the session will fail completely.

This is the case if the server for example runs Windows NT 4.0. If the server has NBT enabled, it listens on
UDP ports 137, 138, and on TCP ports 139, 445.

If it has NBT disabled, it listens on TCP port 445 only.

If you want it to never use anything but port 445, disable NBT.

Created an access-list on the LAN interface of internal LAN traffic going out.

ip access-list extended LAN
deny ip host 172.20.19.255 any
deny ip host 172.20.19.0 any
deny ip host 0.0.0.0 any
deny tcp 172.20.19.0 0.0.0.255 any eq 135
deny udp 172.20.19.0 0.0.0.255 any eq 136
deny udp 172.20.19.0 0.0.0.255 any eq netbios-ns
deny udp 172.20.19.0 0.0.0.255 any eq netbios-dgm
deny tcp 172.20.19.0 0.0.0.255 any eq 139
permit ip 172.20.19.0 0.0.0.255 172.20.0.0 0.0.255.255
permit ip 172.20.19.0 0.0.0.255 any
!
!
Assign ACL to Vlan Interface:

config t
interface vlan 1
ip access-group LAN in

Resulting in :

show ip access-list LAN

Extended IP access list LAN
5 deny ip host 172.20.19.255 any
10 deny ip host 172.20.19.0 any
15 deny ip host 0.0.0.0 any (17 matches)
20 deny tcp 172.20.19.0 0.0.0.255 any eq 135 (207211 matches)
25 deny udp 172.20.19.0 0.0.0.255 any eq 136
30 deny udp 172.20.19.0 0.0.0.255 any eq netbios-ns (1622677 matches)
35 deny udp 172.20.19.0 0.0.0.255 any eq netbios-dgm (5305 matches)
40 deny tcp 172.20.19.0 0.0.0.255 any eq 139 (107979 matches)
45 permit ip 172.20.19.0 0.0.0.255 172.20.0.0 0.0.255.255 (7586488 matches)
50 permit ip 172.20.19.0 0.0.0.255 any (262280 matches)