The revised DNS.EXE that was released in response to MS08-037



Apparently the Windows 2003 server now has the behavior that it
pre-allocates at startup 2500 UDP ports. Can someone explain to me what
these ports are being used for?

Our domain controllers are protected by firewalls, and we have glued all of
the domain controller services (after a lot of painful research and
experiment) to fixed TCP and UDP ports. I'm really concerned if the DNS
server is allocating 2500 random UDP server ports and expecting clients to
come in on those random ports, because I'm fairly certain everything except
TCP and UDP 53 will be blocked for incoming connections.

I would like to understand what it is these ports are being used for, and
how I should go about estimating the number of such ports that need to be
made available to applications on the network.

Is there any way I can force the DNS server to use a specific range of ports
and reduce the number from 2500?

--
W


.



Relevant Pages

  • Re: Whats a decent modem/router for tech savy user?
    ... It is not possible to route or deny traffic to specific ports based on the source IP address. ... But it wont route back inside the LAN - needs internal DNS server spoofing. ... Normally, this option should be Enabled, so that an Internet connection will be made automatically, whenever Internet-bound traffic is detected. ... Specifying a Default DMZ Server allows you to set up a computer or server that is available to anyone on the Internet for services that you haven't defined. ...
    (uk.telecom.broadband)
  • Re: Cannot connect to RWW from home PC
    ... That would be the address you need a DNS record for. ... You say "And in the router you need to forward to your external nic IP" ... Still can't telnet to any of your ports at your public ip address. ... Heres' the info for our server: ...
    (microsoft.public.windows.server.sbs)
  • Re: Netopia 3347NWG with Remote Desktop and Remote Web Workplace
    ... Glad you're back in business Greg! ... Ports Closed ... Despite this, Remote Web Workplace DOES WORK now, and Connect to Server ... Exchange BPA updates), ...
    (microsoft.public.windows.server.sbs)
  • Solution -> Re: SSH tunnel question.
    ... change IPS and ports around but that is not a big deal. ... telnet/ftp/rsh open on a server including on the Internet facing ports! ... I will go from the corp desktop to a hop ... through the firewall to the hop ...
    (SSH)
  • Re: Exch2003 front-end questions
    ... all the supported protocol ports must be open on the inner ... communication between the front-end server and the back-end servers. ... lists the ports required for the intranet firewall. ...
    (microsoft.public.isa)