Re: Windows Firewall on Domain Controllers



Are you talking about Windows 2003 or Windows XP?
By default the Windows 2003 don't activate any FW.

--
I hope that the information above helps you

Good Luck
Jorge Silva
MCSA
Systems Administrator

"Ron" <rhardin@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:68FBE639-4A0C-4982-8F26-C09CC106F976@xxxxxxxxxxxxxxxx
Jorje, thanks for responding. Quick follow-up: you say "don't run a FW on
a
DC", and that was my approach from the beginning. But as I stated,
updates
from Microsoft keep turning the Windows Firewall back on. So how does one
turn it off so it stays off?
--
Ron


"Jorge Silva" wrote:

Hi

* Server 2003 defaults to Windows Firewall active.
* Domain Controller doesn't work with firewally active unless it is
manually
confgured for all the AD ports and you do some voodoo with RPC ports.

Don't use firewall on a DC, use a diferent machine, if you can don't join
the FW to the domain unless you have a good FW solution like ISA 2004 in
a
back to back configuration.

Assuming the above points are correct on my part, what is the best
practice
for administering the firewall on domain controllers (I have about 30
of
them
scattered all over the country)?

Again you shouldn't use a FW on a DC is a bad practice and represents
security issues. Configuring FW on a DC depends on what you need to do
with
it, Applications,DNS,DHCP,Wins,SMB,Replication,etc.

Here's some ports to take:

By default, Active Directory replication over RPC (Remote Procedure
Calls)
takes place dynamically over an available port via the RPC Endpoint
Mapper
(RPCSS) using port 135;

Application protocol Protocol Ports
Global Catalog Server TCP 3269
Global Catalog Server TCP 3268
LDAP Server TCP 389
LDAP Server UDP 389
LDAP SSL TCP 636
LDAP SSL UDP 636
IPsec ISAKMP UDP 500
NAT-T UDP 4500
RPC TCP 135
RPC randomly allocated high TCP ports TCP 1024 - 65536

832017 Service overview and network port requirements for the Windows
Server system
http://support.microsoft.com/default.aspx?scid=kb;EN-US;832017

224196 Restricting Active Directory replication traffic to a specific
port
http://support.microsoft.com/default.aspx?scid=kb;EN-US;224196


--
I hope that the information above helps you

Good Luck
Jorge Silva
MCSA
Systems Administrator

"Ron" <rhardin@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:301A5C97-58EC-426D-B43E-4891BB4E10C0@xxxxxxxxxxxxxxxx
Need input on recommended best practices. Here's what I've figured
out:

* Server 2003 defaults to Windows Firewall active.
* Domain Controller doesn't work with firewally active unless it is
manually
confgured for all the AD ports and you do some voodoo with RPC ports.
* Making a 2003 Server a Domain Controller doesn't automatically
configure
the firewall
* Turning off the firewall only fixes the problem temporarily because
some
Windows Updates automatically turn it back on (without telling you).

Assuming the above points are correct on my part, what is the best
practice
for administering the firewall on domain controllers (I have about 30
of
them
scattered all over the country)?

--
Ron Hardin, CHTP
Director of Technology
Davidson Hotel Company





.



Relevant Pages

  • Re: DCOM 10009 errors on SBS2008 with NAS
    ... make a specific GP rule that allows the ports to that NAS unit. ... The DCOM event id 10009 will occur when a client workstation has a miss-configured firewall or other issues affecting its network communications within the domain, for example if the workstation is not managed by an SBS GPO. ... Depending on your firewall solution this might be implemented or might require opening several ports. ... If the workstation is on a different subnet than the SBS server and it is running Windows XP SP2 or higher, the firewall exceptions provided by the SBS group policies will not properly allow the required connectivity. ...
    (microsoft.public.windows.server.sbs)
  • Re: XP SP2 and ports required to view a remote event log
    ... So for Windows XP SP2 with an enabled firewall, to handle this, ... Group Policy Settings Reference for Windows XP Professional Service Pack 2 ... Windows Firewall: Allow remote administration exception ... TCP ports 135 and 445. ...
    (microsoft.public.windowsxp.setup_deployment)
  • Re: [fw-wiz] how prevelant
    ... over the same few ports), and the tendency of script kiddies to run ... Windows attack tools, I tend to suggest that if you open your firewall up ... > it amazing they were passing domain information across the internet. ...
    (Firewall-Wizards)
  • RE: IM Programs
    ... want to block these ports. ... you don't need an explicit deny for the other ports. ... Access-list 101 deny any tcp any any eq 5000 ... >Now, when applying these to your firewall, make sure the number ...
    (Security-Basics)
  • Re: NETFW.INF, Preconfigured Firewall settings and dialogs
    ... it is Windows Server 2003 SP1 firewall that i'm using. ... Using the document '832017 Port Requirements for the Microsoft Windows ... > to achieve the following goal: some ports are open by default and others ...
    (microsoft.public.windows.server.networking)