Re: Ports require to open to allow communications between AD 2003
- From: "Paul Bergson [MVP-DS]" <pbergson@xxxxxxxxxxxxxxxxx>
- Date: Fri, 5 Jan 2007 11:22:10 -0600
Her eis a Microsoft link
http://support.microsoft.com/kb/179442/en-us
Also I have some info on locking ports to specific ranges for RPC in general
for AD
Check out http://www.pbbergs.com
Select articles and click on Firewall Ports Needed For Replication there is
info and pointers to KB articles
--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT
http://www.pbbergs.com
Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.
"Herb Martin" <news@xxxxxxxxxxxxxx> wrote in message
news:excZsxHMHHA.1240@xxxxxxxxxxxxxxxxxxxxxxx
"Shann Lim" <ShannLim@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:AF9527D2-0514-4F40-836B-7F1C853C4AC4@xxxxxxxxxxxxxxxx
Hi,
Thanks for e advice, appreciate it. We are not looking in VPN cos the
clients are not connected to Internet.
The Internet is neither important nor necessary to the idea of
a VPN.
We were suggesting that you let the clients connect through
a VPN that is allowed to penetrate your firewall. (You can
use authentication to get the clients validated for that VPN
connection too.)
Something like DMZ. The AD are within 10.20.X.X, clients within192.X.X.X.
Firewall between them.
Open a VPN through firewall, but only for clients that can
authenticated (VPN user credentials, IPSec, RADIUS or
some such).
I read the articles u given to me but it is for replication. I am
looking
out more on ports to allow clients
to communicate with AD. Any ideas?
Yes, you can get those either through the articles Laura gave you
or through other similar ones....
Just Google:
[ site:microsoft.com "active directory" authenticate open ports ]
...or some such -- I have found this easily on past occasions, so let
me know if you cannot find it yourself.
.
- Follow-Ups:
- References:
- Re: Ports require to open to allow communications between AD 2003 and
- From: Laura E. Hunter [MVP]
- Re: Ports require to open to allow communications between AD 2003 and
- From: Herb Martin
- Re: Ports require to open to allow communications between AD 2003
- From: Herb Martin
- Re: Ports require to open to allow communications between AD 2003 and
- Prev by Date: Re: In domain.company.com "domain" is not technically a child in a single domain 1 DC AD?
- Next by Date: Re: Adding pc to the domain
- Previous by thread: Re: Ports require to open to allow communications between AD 2003
- Next by thread: Re: Ports require to open to allow communications between AD 2003
- Index(es):
Relevant Pages
|