You can configure your clients to use the SSL port (636) and block the vanilla LDAP port (389) via a firewall.