Re: the protocols&ports required for win2000 DCs' synchronize

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Phillip Windell (_at_.)
Date: 07/22/04


Date: Thu, 22 Jul 2004 08:39:35 -0500

By the time you'd do that, there isn't much point in having the firewall.

-- 
Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com
"seraph" <redseraph@163.com> wrote in message
news:1b5d01c46f95$b0b18250$a601280a@phx.gbl...
> We will setup some win2000 DCs in our network environment,
> but the firewall separate those DCs.
> Which ports should be allowed to let the DCs can
> communicated with each other successfully?
> I am not sure the list below is suitable.
>
>
> UDP/TCP 53 (DNS)
> UDP/TCP 88 (Kerberos authentication)
> TCP 123 (Network Time Protocol-NTP)
> TCP 135 RPC
> TCP 445 (Microsoft Directory Service)
>
>


Relevant Pages

  • Re: Code Red Doesnt care about TCP sessions?
    ... Code Red Doesn't care about TCP sessions? ... I also neglected to state that I've correlated this activity to firewall ... >> from the Web server before it sent it's ACK and then GET request. ...
    (Incidents)
  • Re: [Full-disclosure] 0trace - traceroute on established connections
    ... variety of different probes using both UDP and TCP layer-4 protocols. ... elicit ICMP "TTL exceeded" from hosts in the path, LFT can send TCP ... a tool to probe firewall ACLs; ...
    (Full-Disclosure)
  • Re: [Full-disclosure] 0trace - traceroute on established connections
    ... For example, rather than only launching UDP probes in an attempt to elicit ICMP "TTL exceeded" from hosts in the path, LFT can send TCP SYN or FIN probes to target arbitrary services. ... a tool to probe firewall ACLs; ...
    (Bugtraq)
  • Re: NTFRSUTIL error 1753
    ... So what you are suggesting is that I do not start the windows firewall ... service on both my dcs. ... issue even when I hard code the ports in the registry it seems not to work ...
    (microsoft.public.windows.server.active_directory)
  • Re: R2 DFS Replication failing
    ... Disabled the firewall and everything started magically working.. ... BTW: Found out the RPC patch is this one: ... System service name: DfsApplication protocol Protocol Ports ... NetBIOS Session Service TCP 139 ...
    (microsoft.public.windows.server.general)