Open ports? a member server behind a firewall.

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Ulrik (ulrix_at_hotmail.com)
Date: 07/05/04


Date: Mon, 5 Jul 2004 20:01:24 +0200

Hi

Windows 2003 Active Directory and Windows 2003 member server.
The member server is behind a firewall. The rest of the Windows 2003 domain
are located on an Intranet.

What ports are needed to be open from the member server to Domain Controller
to authenticated and be a domain member?

This are the ports I guess I have to open (from member to DC)
ICMP/Echo (ping)
UDP/TCP 53 (DNS)
UDP/TCP 88 (Kerberos authentication)
UDP/123 (Network Time Protocol-NTP)
UDP/TCP 389 (LDAP Access)
TCP 445 (Microsoft Directory Service)
UDP/137 Permit NetBIOS Name Resolution
UDP/138 Permit NetBIOS Datagram Service
TCP/139 Permit NetBIOS Session Service

I guess I also need this ports?
TCP 135 (RPC Endpoint Mapper)
I'll need to allow one high port for Active Directory logon, greater than
1024. (The one you can get static through a reghack)

Do I need to open any port from the Domain Controller to the member server?

Best regards

/Ulrik



Relevant Pages

  • Re: Nt4 client - W2k3 member server in NT Domain
    ... The URL provided by Timmy is the download link for Active Directory ... Extension for Windows NT 4.0. ... |located in the NT4 ... |>issues accessing the W2K3 member server in the NT4 ...
    (microsoft.public.windows.server.migration)
  • RE: krb5kdc_err_s_principal_unknown on Windows Kerberos Domain
    ... Install the Microsoft Resource Kit on the member server and/or workstation ... command line with the parameter "tickets". ... krb5kdc_err_s_principal_unknown on Windows Kerberos Domain ... SPN for the domain with SetSPN, but I would like to a) get help determining ...
    (comp.protocols.kerberos)
  • Re: upgrade question
    ... If the SBS will let you convert it to a member server first, ... > I'm close to migrating from a SBS2000 domain to a full Windows 2003. ... Also setup DNS on this machine and make it a GC. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Win 2000 member; Win 2003 domain controller
    ... Is it possible to have a windows 2000 member server in a ... I have a Win2003 Active Directory Domain and I am trying ... account has been added to the win2003 active directory. ...
    (microsoft.public.win2000.active_directory)
  • Re: Readd access to view local groups
    ... Usually domain users can view the Local Users ... I have a Windows 2003 member server in Active Directory. ...
    (microsoft.public.windows.server.general)