Re: Windows Ports when used on DMZ

From: S. Pidgorny (slavickp_at_yahoo.com)
Date: 06/28/05


Date: Tue, 28 Jun 2005 19:02:07 +1000

When I was doing testing, the absolute minimum was - RPC with 1 static port,
DNS (UDP only is sufficient if no long response is expected), CIFS direct
hosting (445/TCP), Kerberos/UDP, LDAP (TCP, enable UDP which is "LDAP ping"
to keep firewall logs clean), LDAP GC over TCP, Kerberos/UDP and ICMP ping
(firewalls do filtering based on ICMP message number).

-- 
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-
"Steven L Umbach" <n9rou@nospam-comcast.net> wrote in message
news:#TOfxezeFHA.220@TK2MSFTNGP12.phx.gbl...
> See the links below for details from a KB article that discusses such.
More
> than likely your problem is with dynamic RPC in that you are finding ports
> 1025-1030 being dropped by your firewall.  You can configure dynamic RPC
to
> use a limited number of ports and then configure your firewall to allow
> them. --- Steve
>
> http://support.microsoft.com/?id=154596
> http://support.microsoft.com/kb/179442/
>
> "Derek Smith" <smithdl@sanjuancollege.edu> wrote in message
> news:OGxhGKzeFHA.1680@TK2MSFTNGP09.phx.gbl...
> > Hi,
> >
> > We have a Windows Server on a DMZ, and it's having trouble querying
Active
> > Directory.  We have a PIX and have allowed what we thought is everything
> > we need.  Does anyone know exactly what ports are needed to query Active
> > Directory and have all services running with a Windows Box right out of
> > the box?
> >
> > More specifically, we are getting an RPC Error when trying to add
> > administrators to the local groups.  It works fine when we allow all IP,
> > so we know the problem is with the PIX.
> >
> > Thanks in advance,
> >
> > Derek Smith
> >
>
>


Relevant Pages

  • Re: [Full-Disclosure] Cox is blocking port 135 - off topic
    ... > specifically configured RPC port on the remote ... For intranet environments, these ports are ... > hostile environments, such as the Internet. ... > used on the internet and you need a firewall to block ...
    (Full-Disclosure)
  • Re: Firewall Windows 2003 Server SP1
    ... Ich mach einfach SMB, RPC, LDAP, etc zu, dann kann mich keiner ... Ich meinte eigentlich das hier bzgl. der dynamischen Ports bezogen auf die ... In früheren Windows-Versionen wurde die RPC-Kommunikation von der Windows ... Firewall blockiert. ...
    (microsoft.public.de.german.windows.server.networking)
  • Re: RPC ports over a firewall
    ... > 1) Does the RPC need to be restricted to a static port on ServerB as well ... you restrict RPC to a small number of ports. ... UDP 88 Kerberos Authentication ...
    (microsoft.public.windows.server.active_directory)
  • Re: Windows Firewall on Domain Controllers
    ... * Domain Controller doesn't work with firewally active unless it is ... confgured for all the AD ports and you do some voodoo with RPC ports. ... Don't use firewall on a DC, use a diferent machine, if you can don't join ... Active Directory replication over RPC ...
    (microsoft.public.windows.server.active_directory)
  • Re: R2 DFS Replication failing
    ... Disabled the firewall and everything started magically working.. ... BTW: Found out the RPC patch is this one: ... System service name: DfsApplication protocol Protocol Ports ... NetBIOS Session Service TCP 139 ...
    (microsoft.public.windows.server.general)