running ISA on DC

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



the machine has two NICs, one for the internal network & one for the router.
I'm not concerned with Exchange or anything else, only the ability to
authenticate & replicate with another DC and host a global catalog. I'm not
using the firewall client but have that option enabled in the system policy
so that
file sharing is enabled (gotta connect to sysvol to run scripts)...

is the following list only what's needed from 'internal' to 'local host'?:

DNS
Kerberos-Sec (TCP)
Kerberos-Sec (UDP)
LDAP
LDAP (UDP)
LDAP GC (Global Catalog)
LDAPS
LDAPS GC (Global Catalog)
Microsoft CIFS (TCP)
Microsoft CIFS (UDP)
NetBios Datagram -- necessary?
NetBios Name Service -- necessary?
NetBios Session -- necessary?
Ping
RPC Server (all interfaces)

am i adding some unnecessary stuff?




.



Relevant Pages

  • Re: does .net network security depend on netios ?
    ... security API calls under the hood, not LDAP, to resolve SIDs in a token into ... LDAP doesn't require NETBIOS to my knowledge, ...
    (microsoft.public.dotnet.security)
  • Re: does .net network security depend on netios ?
    ... are required if you use the straight LDAP API or not. ... > ADSI LDAP queries seem to need these on my machine ... ... I think those APIs still use NETBIOS for backward ...
    (microsoft.public.dotnet.security)
  • Re: running ISA on DC
    ... > Kerberos-Sec (UDP) ... > LDAP ... > NetBios Name Service -- necessary? ... > RPC Server ...
    (microsoft.public.isaserver)
  • Re: LDAP Query witn netbios name fails in 2003
    ... I actually don't use the WinNT provider ever and only really deal with LDAP, ... > Hi Joe; ... >> additional translation for the NETBIOS name to work and some features ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD replication across firewall using limited RPC
    ... -- RPC (you will set this to a static port) ... -- Global catalog LDAP ... -- Global catalog LDAP over SSL ...
    (microsoft.public.windows.server.active_directory)