Re: Help Understanding LDAP Variants
- From: "Will" <westes-usc@xxxxxxxxxxxxxx>
- Date: Wed, 3 Jan 2007 19:07:15 -0800
"Joe Richards [MVP]" <humorexpress@xxxxxxxxxxx> wrote in message
news:eK3Ovy0LHHA.320@xxxxxxxxxxxxxxxxxxxxxxx
The GC ports are used A LOT by normal Windows operations - it is how
Windows finds things in the directory. For instance START | SEARCH |
PRINTERS, COMPUTERS, OR PEOPLE will hit the GC.
Thanks for that.
If you don't have certs on the DCs the ports are effectively dead. Appsoff.
will connect to the port and send a SSLV2 Hello and then get bounced by
the DS service when it realizes it doesn't have a cert. Nothing else on
the DC should be able to use those ports as LSASS will grab them right
Great to know as well.
Obviously if you really want to know if you can block a port, the best
way is to do a long term trace on the machine for the ports in question
and look at what is coming through. Untold numbers of issues have been
caused by people just throwing up traffic filters and then having no
clue how it will impact them and then when weird things occur don't make
the connection with the changes they made. From that you can probably
see that I am not a proponent of firewalling between DCs any anything.
Yes, but in our case we examine the firewall logs frequently, and run dcdiag
/v on each of two domain controllers in a domain that uses the firewalls,
and we have studied the problem of puttng a domain controller behind a
firewall in a lab environment for a long time now.
I do understand that the craziness of the current era of computing is that
operating systems are starting to *look* like they are easy to use and
configure, when in fact they are still hideously complex, and non standard
configurations are non trivial. At the same time the people who sometimes
get charged with running these things don't know what to look at to diagnose
issues, and don't understand computer and network architecture issues well.
So of course the support groups never want to recommend any configuration
that puts a domain controller behind a firewall, because that will mean
another 14 hours on the phone getting all the pieces to work.
--
Will
.
- Follow-Ups:
- Re: Help Understanding LDAP Variants
- From: Joe Richards [MVP]
- Re: Help Understanding LDAP Variants
- References:
- Re: Help Understanding LDAP Variants
- From: Will
- Re: Help Understanding LDAP Variants
- From: Joe Richards [MVP]
- Re: Help Understanding LDAP Variants
- Prev by Date: Re: edb.chk edb.log and tmp.edb
- Next by Date: Re: whenCreated Date Format
- Previous by thread: Re: Help Understanding LDAP Variants
- Next by thread: Re: Help Understanding LDAP Variants
- Index(es):
Relevant Pages
|