DTC Through Firewall. Port Limitation Not Working



Hi I am experiencing problems limiting the dynamic ports used by MSDTC. The
problem we are seeing is on a production box that we are trying to deploy to.
I cannot replicate the issue we are seeing on the live boxes in any test
scenario. The production servers live in an environment which has some very
severe change managing policies and the servers are separated by a firewall.

We have been trying to limit the ports required for DTC through the
Component Services Snap-In >> Default Protocols. After a restart we have then
been using Microsoft Network Monitor to monitor traffic when using the DTC
ping tool. It currently appears that whilst one of the servers is correctly
assigning out ports from the pool we setup the the other server does not seem
to see the ports we have setup and is still using ports in the low 1000's
rather than 5000-5100 as per our setup. I cannot explain this as all my tests
on test boxes work first time after a restart.

There is friction with my client at the minute as these are production boxes
and every server restart has to be requested through change management and
takes a day or two to organise. We are also running behind a deadline to get
this application up and running so the pressure is really on.

I cannot really ask my client to restart the servers any more without a good
reason or without making some solid configuration change that we are almost
certain will work.

I am really clutching at straws for ideas now and am at a loss as to why our
setup isn't working on the production boxes. So what I really need to know is
why would the ports setup in the DCOM config be ignored?

.



Relevant Pages

  • Re: Hardening Windows 2000
    ... > We have a requirement to "harden" the operating system on production ... > Windows 2000 servers. ... > and deleted the ports that we considered unnecessary? ... this does not help/work on unix, so does it not do anything on windows. ...
    (comp.security.misc)
  • Re: OWA 2003 in DMZ ??
    ... Thought I answered that but let me reiterate: High security is not ... something you'll be able to accomplish in that scenario that you have setup. ... Ports are mostly the same as E2K in E2K3. ... server will talk with. ...
    (microsoft.public.exchange.admin)
  • Re: Visa PCI Firewall Requirements and Windows Networks
    ... GP without the risk of open ports or a DC in the DMZ. ... Outbound access should be minimized but if windows update is your ... alternative tools on trusted servers to patch your machine. ... > behind the second firewall. ...
    (Focus-Microsoft)
  • Re: HACKING SOFTWARE
    ... You know there is more to just running nmap on people's servers. ... ICMP requests and I have no open ports what so ever (not just firewalled - ... That's CIA crap!" ...
    (alt.2600)
  • Re: HACKING SOFTWARE
    ... You know there is more to just running nmap on people's servers. ... ICMP requests and I have no open ports what so ever (not just firewalled - ... the hell to compile a recent version of Nmap, so I use a real old Windows ...
    (alt.2600)

Loading