Re: Allowing all AD traffic to DCs

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Check out an article I have on this at:
http://www.pbbergs.com/windows/articles.htm

Select Firewall ports needed for replication

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

"supersonic_oasis" <supersonicoasis@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message news:646EB09B-AF9D-47DF-9A79-1695B6BE8326@xxxxxxxxxxxxxxxx
Hi all,

We run Windows 2003 domain. I am having trouble opening the proper ports
on
all DCs needed for proper functionality of FRS, and group policy. I
remember
I looked at a microsoft white paper a while back, and everything worked
fine, but we've been having trouble with group policy lately, so I checked
the firewall log and saw that traffic between DCs is getting dropped. And
it
seems every time I open a port that is being blocked, another one pops up.

Can anyone give me a complete list of every port that needs to be opened
for
DC to DC traffic. Or, is there an easier way using the windows Firewall?
For instance, can I somehow make it so that if any traffic comes from a
certain IP, then allow it?

Any help is appreciated, thanks.


.



Relevant Pages

  • Re: File sharing
    ... Instead of creating exceptions for individual ports for FPS I suggest that you try Group Policy and configuring the exemption for file and print sharing and probably the remote administration exemption. ... If there are do domain level Group Policies being applied to these computers currently for Windows Firewall, which you could verify by running rsop.msc on the client computer, you could try using local Group Policy to see if it does what you want. ... So then I went back and put in a custom setting to accept connections on the local subnet plus connections from my subnet, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Root exploit for FreeBSD
    ... for two ports to my FreeBSD portscluster nodes. ... and it gives the firewall ... US this is also quite common, at least with regards to University ... if your computer is going to connect on our network it must be configured in certain ways and behave "normally" or you won't get a connection. ...
    (freebsd-questions)
  • Re: Root exploit for FreeBSD
    ... for two ports to my FreeBSD portscluster nodes. ... and it gives the firewall ... US this is also quite common, at least with regards to University ... if your computer is going to connect on our network it must be configured in certain ways and behave "normally" or you won't get a connection. ...
    (freebsd-current)
  • Re: Trouble accessing Outlook Web Access from behind firewall
    ... When starting the firewall I also set ... > rejected and dropped packets are logged, however I see nothing in my log ... > # Higher ports needed to accept incoming/outgoing calls ...
    (comp.security.firewalls)
  • Re: iptables configuration
    ... >> that if a 'virus/trojan' initiated a connection to the net, the firewall ... >> would not protect the LAN. ... The LAN is NATed with private IPs to one public IP. ... the ports that are used by services running on linux. ...
    (comp.os.linux.security)