Re: Windows Firewall on Domain Controllers

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



yes

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
"sprucio" <sprucio@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:39B26276-3B37-44CE-813B-145A1495E030@xxxxxxxxxxxxxxxx
Have any of you guys read this article?

http://support.microsoft.com/default.aspx?scid=kb;en-us;555381&sd=rss&spid=3198

I have tried this but had no success so far.

"Jorge de Almeida Pinto [MVP]" wrote:

the firewall on a fresh installed w2k3sp1 server is NOT on by default!

it is only on during the post-security updates section. as soon as you
update the server you need to click finish and read the message stating
it
will allow inbound connections

don't use the firewall on the DC

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no
rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
"Ron" <rhardin@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:301A5C97-58EC-426D-B43E-4891BB4E10C0@xxxxxxxxxxxxxxxx
Need input on recommended best practices. Here's what I've figured
out:

* Server 2003 defaults to Windows Firewall active.
* Domain Controller doesn't work with firewally active unless it is
manually
confgured for all the AD ports and you do some voodoo with RPC ports.
* Making a 2003 Server a Domain Controller doesn't automatically
configure
the firewall
* Turning off the firewall only fixes the problem temporarily because
some
Windows Updates automatically turn it back on (without telling you).

Assuming the above points are correct on my part, what is the best
practice
for administering the firewall on domain controllers (I have about 30
of
them
scattered all over the country)?

--
Ron Hardin, CHTP
Director of Technology
Davidson Hotel Company





.



Relevant Pages

  • Re: user security tab
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... * This posting is provided "AS IS" with no warranties and confers no rights! ...
    (microsoft.public.win2000.active_directory)
  • Re: R2 in-place upgrade bug ? ..HELP
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... unnecessarily go to the firewall then pass on thru to the host. ... Jorge Silva wrote: ...
    (microsoft.public.windows.server.active_directory)
  • Re: Disable all accounts who havent logged on prior to certain date
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... * This posting is provided "AS IS" with no warranties and confers no rights! ...
    (microsoft.public.windows.server.active_directory)
  • Re: Unauthorize DHCP server from Authorized list
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... * This posting is provided "AS IS" with no warranties and confers no rights! ... unauthorize: "There is no such object on the server" ...
    (microsoft.public.windows.server.active_directory)
  • Re: Firewall between DC and member servers
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... * This posting is provided "AS IS" with no warranties and confers no rights! ... Firewall rules and you see what happens. ...
    (microsoft.public.windows.server.active_directory)