If you have samba configured and also have a active firewall, in that case you need to allow only these specific ports for letting windows machines to communicate with your samba server.
So restricting or blocking un-wanted ports will always help in strengthening the security.
netbios-ns – 137/tcp # NETBIOS Name Service
netbios-dgm – 138/tcp # NETBIOS Datagram Service
netbios-ssn – 139/tcp # NETBIOS session service
microsoft-ds – 445/tcp # if you are using Active Directory
A simple screenshot for your reference.