Re: What LDAP Ports thru DMZ



At a minimum you need port 389 to query the domain and 3268 to query the
global catalog. If you will use SSL/LDAP, you need 636 and 3269
respectively.

Depending on the type of authentication you will do to AD, you may also need
Kerberos (port 88 TCP and UDP) and may need RPC (135 at a minimum).

When you say the LDAP server will be in the DMZ, are you setting up some
kind of LDAP proxy server or are you saying that the LDAP client application
(like a web server) will be in the DMZ? Generally you wouldn't need a
different LDAP server to talk to AD, although I suppose you could do that.

There is also another way to communicate with AD using the DSML server. It
allows you to make HTTP/SOAP calls to a web server that is essentially an
LDAP proxy. In that case, your firewall issues are just standard HTTP
things (80/443) if you put the DSML server behind the firewall. There is a
fairly straightforward way to program this if you are using .NET 2.0 and the
System.DirectoryServices.Protocols namespace.

Joe K.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services Programming"
http://www.directoryprogramming.net
--
"Chris Davoli" <ChrisDavoli@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:629D56D8-DAA7-40FD-8F70-8DE6204CFB09@xxxxxxxxxxxxxxxx
I am going to use LDAP to look up userids on an active directory server.
The
LDAP server is on the outside in the DMZ. The Active Directory server is
on
the inside, so holes need to be poked into the firewall. My question is,
what
ports need to be poked into the firewall so I can read active directory?
--
Chris Davoli



.



Relevant Pages

  • Re: Active Directory
    ... you can provide ldp with a null value for the server name and it ... There is generally no reason to change the port as AD always uses port 389 ... Joe Kaplan-MS MVP Directory Services Programming ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ...
    (microsoft.public.windows.server.security)
  • Re: Can LDAP port designation be changed for AD in W2K
    ... Especially another LDAP server. ... > I'm running into port conflicts between Active Directory ...
    (microsoft.public.windows.server.active_directory)
  • RE: Some technical errors
    ... If the SMTP server is not running on port 25 TCP it is not a public ... Manager - Computer Assurance Services BDO Chartered Accountants & ...
    (Security-Basics)
  • Re: SRV RRs support in Internet Explorer?
    ... The port number could be implicit (i.e. ... At any point in time, a server could fail ... can't effectively LB or backup because NSs cache the records for the TTL ... I still don't see how SRV records would help backup or LB. ...
    (microsoft.public.win2000.dns)
  • Re: Still cant connect to RWW or OWA remotely
    ... I get 'cannot find server or dns error' on both ... TCP [port number]> to open the ports. ... As for error messages when I fail to access RWW with the laptop, ... network, no connection seems possible. ...
    (microsoft.public.windows.server.sbs)