Re: Windows 2003 Server with ICF
From: Miha Pihler (mihap-news_at_atlantis.si)
Date: 08/15/04
- Next message: Gordon: "DHCP Installation"
- Previous message: Sam Cheung: "Windows 2003 Server with ICF"
- In reply to: Sam Cheung: "Windows 2003 Server with ICF"
- Next in thread: MAX-007: "Re: Windows 2003 Server with ICF"
- Reply: MAX-007: "Re: Windows 2003 Server with ICF"
- Messages sorted by: [ date ] [ thread ]
Date: Sun, 15 Aug 2004 20:51:07 +0200
Hi Sam,
I wouldn't recommend enabling ICF on domain controllers (DCs). LAN should be
trusted part of the network.
Here is list of some TCP ports required by DCs
RPC endpoint mapper 135/tcp, 135/udp
NetBIOS name service 137/tcp, 137/udp
NetBIOS datagram service 138/udp
NetBIOS session service 139/tcp
RPC dynamic assignment 1024-65535/tcp
SMB over IP (Microsoft-DS) 445/tcp, 445/udp
LDAP 389/tcp
LDAP over SSL 636/tcp
Global catalog LDAP 3268/tcp
Global catalog LDAP over SSL 3269/tcp
Kerberos 88/tcp, 88/udp
DNS 53/tcp[1], 53/udp
WINS resolution (if required) 1512/tcp, 1512/udp
WINS replication (if required) 42/tcp, 42/udp
Network time protocol (NTP) 123/udp
Clients use broadcasts to discover DHCP servers.
For IIS if you use default installation you will have to open TCP port 80.
File server will be open if you open above ports.
Again, personally I wouldn't use any kind of filtering software on domain
controllers.
Mike
"Sam Cheung" <SamCheung@discussions.microsoft.com> wrote in message
news:B584457F-5364-48C0-A7AC-5A6070A7AC9B@microsoft.com...
> I have a network with some Win2k3 server and 100 winXP clients, which have
> function running as DC, DHCP server, DNS server, IIS, File Server...etc.
I
> also turn on the ICF function on each server to have higher protection.
> But I don't know which port I need to open of each services, can anyone
tell
> me which port and which type port (TCP/UDP) need to open for each
services?
>
>
- Next message: Gordon: "DHCP Installation"
- Previous message: Sam Cheung: "Windows 2003 Server with ICF"
- In reply to: Sam Cheung: "Windows 2003 Server with ICF"
- Next in thread: MAX-007: "Re: Windows 2003 Server with ICF"
- Reply: MAX-007: "Re: Windows 2003 Server with ICF"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|