Re: Windows Firewall on Domain Controllers



Hi

* Server 2003 defaults to Windows Firewall active.
* Domain Controller doesn't work with firewally active unless it is
manually
confgured for all the AD ports and you do some voodoo with RPC ports.

Don't use firewall on a DC, use a diferent machine, if you can don't join
the FW to the domain unless you have a good FW solution like ISA 2004 in a
back to back configuration.

Assuming the above points are correct on my part, what is the best
practice
for administering the firewall on domain controllers (I have about 30 of
them
scattered all over the country)?

Again you shouldn't use a FW on a DC is a bad practice and represents
security issues. Configuring FW on a DC depends on what you need to do with
it, Applications,DNS,DHCP,Wins,SMB,Replication,etc.

Here's some ports to take:

By default, Active Directory replication over RPC (Remote Procedure Calls)
takes place dynamically over an available port via the RPC Endpoint Mapper
(RPCSS) using port 135;

Application protocol Protocol Ports
Global Catalog Server TCP 3269
Global Catalog Server TCP 3268
LDAP Server TCP 389
LDAP Server UDP 389
LDAP SSL TCP 636
LDAP SSL UDP 636
IPsec ISAKMP UDP 500
NAT-T UDP 4500
RPC TCP 135
RPC randomly allocated high TCP ports TCP 1024 - 65536

832017 Service overview and network port requirements for the Windows
Server system
http://support.microsoft.com/default.aspx?scid=kb;EN-US;832017

224196 Restricting Active Directory replication traffic to a specific port
http://support.microsoft.com/default.aspx?scid=kb;EN-US;224196


--
I hope that the information above helps you

Good Luck
Jorge Silva
MCSA
Systems Administrator

"Ron" <rhardin@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:301A5C97-58EC-426D-B43E-4891BB4E10C0@xxxxxxxxxxxxxxxx
Need input on recommended best practices. Here's what I've figured out:

* Server 2003 defaults to Windows Firewall active.
* Domain Controller doesn't work with firewally active unless it is
manually
confgured for all the AD ports and you do some voodoo with RPC ports.
* Making a 2003 Server a Domain Controller doesn't automatically configure
the firewall
* Turning off the firewall only fixes the problem temporarily because some
Windows Updates automatically turn it back on (without telling you).

Assuming the above points are correct on my part, what is the best
practice
for administering the firewall on domain controllers (I have about 30 of
them
scattered all over the country)?

--
Ron Hardin, CHTP
Director of Technology
Davidson Hotel Company


.



Relevant Pages

  • Re: [Full-Disclosure] Cox is blocking port 135 - off topic
    ... > specifically configured RPC port on the remote ... For intranet environments, these ports are ... > hostile environments, such as the Internet. ... > used on the internet and you need a firewall to block ...
    (Full-Disclosure)
  • Re: Adding additionl DC to existing windows 2003 Domain
    ... Paul is probably right in respect of the ports being blocked. ... If your wan connection does not go through a firewall and only throught the ... I have added the new windows 2003 server to the ... "Could not find the domain controller for this domain." ...
    (microsoft.public.windows.server.active_directory)
  • Re: Help Understanding LDAP Variants
    ... PRINTERS, COMPUTERS, OR PEOPLE will hit the GC. ... way is to do a long term trace on the machine for the ports in question ... Yes, but in our case we examine the firewall logs frequently, and run dcdiag ... that puts a domain controller behind a firewall, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Windows 2003 Domain Controller (Open Port 593)
    ... says placing a DC so firewall separates it from its members is not ... This approach allows you to take just the RPC services required for a domain ... That way you do NOT open up ranges of ports on the ... be able to open up a secure channel to the domain controller, ...
    (microsoft.public.windows.server.security)
  • Re: Firewall Windows 2003 Server SP1
    ... Ich mach einfach SMB, RPC, LDAP, etc zu, dann kann mich keiner ... Ich meinte eigentlich das hier bzgl. der dynamischen Ports bezogen auf die ... In früheren Windows-Versionen wurde die RPC-Kommunikation von der Windows ... Firewall blockiert. ...
    (microsoft.public.de.german.windows.server.networking)