Re: win2k3 active directory - firewall ports



On 2007-07-20 dubaisans dubai wrote:
i want to put win2k3 active directory server behind the corporate
firewall. we are using windows xp clients and also group policy

what ports need to be allowed on firewall ? is there any fine tuning
that can be done on AD to make it more firewall friendly?

i have some DC is remote locations . what ports need to be allowed
between DCs?

You should not open any ports into your LAN unless you have very, VERY
good reasons to do so. Establish a VPN between your LAN and the remote
locations.

Regards
Ansgar Wiechers
--
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq



Relevant Pages

  • Re: How do I use IPSEC to create a basic firewall.
    ... Ipsec is best used to manage/protect traffic for the lan. ... > secure domain controllers by IPSEC, thus providing a basic firewall ... > response ports opened by connections going to the WAN. ...
    (microsoft.public.win2000.security)
  • Re: Trouble accessing Outlook Web Access from behind firewall
    ... When starting the firewall I also set ... > rejected and dropped packets are logged, however I see nothing in my log ... > # Higher ports needed to accept incoming/outgoing calls ...
    (comp.security.firewalls)
  • Re: Odd nmap result qaz and netbios on Linux
    ... Samba isn't installed anywhere within that lan. ... refer to is a minimal firewall. ... >>the same ports open. ...
    (comp.os.linux.security)
  • Re: iptables configuration
    ... >> that if a 'virus/trojan' initiated a connection to the net, the firewall ... >> would not protect the LAN. ... The LAN is NATed with private IPs to one public IP. ... the ports that are used by services running on linux. ...
    (comp.os.linux.security)
  • Firewall old computer
    ... I also have a home LAN running a W2K Server and Proxy 2.0 ... I want to try and multihome my old P166 and use it as a firewall for ... could you please tell me how to find out all of the ports ...
    (comp.security.firewalls)