Kerberos
Ticket based authentication
Security: Clock skew breaks it; watch for Kerberoasting and ticket forging
TCP / UDP · Encrypted: Yes
Port
Conventionally used by Kerberos. Port assignments are conventions, so confirm the actual listener before you write a rule around this number.
Ticket based authentication
Security: Clock skew breaks it; watch for Kerberoasting and ticket forging
TCP / UDP · Encrypted: Yes
Decide reachability from the identity of the caller, not from the port number. If the service on this port carries credentials or administrative control, restrict it to an administrative network, require strong authentication, and log every session that reaches it.
Open the interactive map centred on this entity to see everything it connects to and travel outwards from there.