Re: unmanageable DNS

Tech-Archive recommends: Fix windows errors by optimizing your registry



In news:8577F63D-6F98-4644-98B9-E9FD255A443C@xxxxxxxxxxxxx,
p.o <po@xxxxxxxxxxxxxxxxxxxxxxxxx> stated, which I commented on below:
Hi

My serves are standing in DMZ zone so I've got blocked many ports.
I've configured AD as Microsoft said and Directory Services works ok.
When I delete registry key
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Internet\ports the mmc snap
working ok (localy and remote) but when I got this reg key I can't
connect to DNS via MMC (localy and remote).

How shoudl I configure DNS to work with static rpc.

Thanks,

Honestly, I've never tried it with DNS, but I can tell you this much: MS DNS
will communicate with other Windows machines (whether thru DNS queries or
simply trying to conenct to the machine using an MMC console), with dynamic
ports. Connecting to a console is not really a DNS port, but rather the RPC
ports. I have not configured such as thing as for RPC traffic, because those
articles depict specific domain RPC traffic. What you're looking for is
standar network communication & authentication between domain members which
includes numerous ports. If you look at those articles, they show what ports
and their ranges are required. Maybe you can create specific rules between
specific machiens allowing those ports, or create a VPN between the DMZ
machine and the internal network, which I've seen many admins have
successfully configured in your type of scenario.

Ace


.



Relevant Pages

  • Re: Is This Normal DNS Behavior on a Server2003 SP2 Domain Controller
    ... Protection against the Microsoft DNS Cache Poisoning Vulnerability ... These response or service ports, are used by all Windows communications. ... How to reserve a range of ephemeral ports on a computer that is running Windows Server 2003 or Windows 2000 Server ...
    (microsoft.public.windows.server.dns)
  • Re: unmanageable DNS
    ... MMC due to RPC problems ... My serves are standing in DMZ zone so I've got blocked many ports. ... connect to DNS via MMC. ... How shoudl I configure DNS to work with static rpc. ...
    (microsoft.public.windows.server.dns)
  • Re: Issue with port blocking on public DNS server
    ... I am talking about the "Destination Ports" in the "Responses to local DNS ... names (other then the domain names in my own DNS server) on the servers. ... Filtering outbound requests on port 53 FROM the DNS to the Internet ...
    (microsoft.public.windows.server.dns)
  • Re: Connecting to Linux machine remotely
    ... The way to connect to a machine from a remote location is via ssh. ... want to connect from which queries the dns server of my ISP every 5 min ... ]> need you can forward tcp ports through ssh. ...
    (comp.os.linux.networking)
  • Re: iptables, NAT, DNS & Dan Kaminsky
    ... in RFC-compliant DNS caching servers the successful execution of which ... I.e. boxes within the NATted LAN which use ... random UDP ports are secure and neither the 2.4.x nor the 2.6.x series ...
    (Linux-Kernel)