Re: Authentication Ports



"Mitch" <Mitch@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:23FA4A82-0F3B-4364-A7DE-F1F1BB188263@xxxxxxxxxxxxxxxx
Hi,
I am setting up a point to point T1 in addition to an IPSec tunnel between 2
offices. In order for everything to communicate with the equipment were
using, I will need the port# for exchange email, system traffic and the port
which Active Directory uses to authenticate users. Does anyone know the
answer to this? Thanks.

Mitch


You are better off just opening the VPN wide open between the locations. The VPN will secure the traffic anyway, so no worries.

Otherwise you must open up a slew of ports to the point it swiss-cheeses the firewall. In addition the Default emepheral ports need to be opened. They are the random service ports that Windows uses to communicate, and are required by AD. They are UDP 1024 - 65535 (See KB179442), but for Vista and Windows 2008 it's different. Their default start port is UDP 49152, and the default end port is UDP 65535 (see KB899148).

Have a read on the following:

======================================================================================================
======================================================================================================

Active Directory Firewall ports

Active Directory Replication over FirewallsJan 31, 2006. Active Directory relies on remote procedure call (RPC)
http://technet.microsoft.com/en-us/library/bb727063.aspx

How to configure a firewall for domains and trusts
http://support.microsoft.com/?id=179442

Configuring an Intranet Firewall, Apr 14, 2006. Protocol ports required for the intranet firewall.
Ports required for Active Directory and Kerberos communications
http://technet.microsoft.com/en-us/library/bb125069.aspx

Active Directory and Firewall PortsI found it hard to find a definitive list on the internet for what ports needed opening for Active Directory to replication between Firewalls. ...
http://geekswithblogs.net/TSCustomiser/archive/2007/05/09/112357.aspx




--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSA Messaging, MCT
Microsoft Certified Trainer
aceman@xxxxxxxxxxxxxxxxxxxxxxx

For urgent issues, you may want to contact Microsoft PSS directly. Please
check http://support.microsoft.com for regional support phone numbers.

"Efficiency is doing things right; effectiveness is doing the right things." - Peter F. Drucker
http://twitter.com/acefekay

.



Relevant Pages

  • Firewall ports for AD domains in 2 different forests--SMS indirect
    ... the below in relation to Active Directory only before I have our Headquarters ... Firewall Team open the ports on the routers: ... Question at bottom and response from SMS Newsgroup below. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Access to user properties
    ... These subnet are separated by a firewall, ... Active Directory communication requires about 29 ports to be allowed through, including the emepheral response ports. ... "To comply with Internet Assigned Numbers Authority recommendations, Microsoft has increased the dynamic client port range for outgoing connections in Windows Vista and in Windows Server 2008. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Root exploit for FreeBSD
    ... for two ports to my FreeBSD portscluster nodes. ... and it gives the firewall ... US this is also quite common, at least with regards to University ... if your computer is going to connect on our network it must be configured in certain ways and behave "normally" or you won't get a connection. ...
    (freebsd-questions)
  • Re: Root exploit for FreeBSD
    ... for two ports to my FreeBSD portscluster nodes. ... and it gives the firewall ... US this is also quite common, at least with regards to University ... if your computer is going to connect on our network it must be configured in certain ways and behave "normally" or you won't get a connection. ...
    (freebsd-current)
  • Re: Trouble accessing Outlook Web Access from behind firewall
    ... When starting the firewall I also set ... > rejected and dropped packets are logged, however I see nothing in my log ... > # Higher ports needed to accept incoming/outgoing calls ...
    (comp.security.firewalls)

Quantcast