Win2k Member Server in DMZ

From: LCI (it_at_lcitoys.com)
Date: 08/27/03


Date: Wed, 27 Aug 2003 12:10:19 -0400


I have a windows 2000 member server that I just put into our DMZ. I
configured the firewall to allow the necesary ports as specified by
Microsoft (88, 123, 135, 389, 445, 3268, and one port above 1024, which i
set in the DCs registry
HKLM/System/CurrentControlSet/Services/NTDS/Parameters). After doing this I
had an extremely slow boot process (20 minutes for boot and another 20 for
login). After reviewing our firewall logs, I discovered that a great deal of
packets were being dropped with a destination port of 1026. I opened that up
and now it works great. Does anyone know why I needed to open this port,
despite any reference to it from any document I can find for putting a
member server in a DMZ? Thanks for your help.

--Jared



Relevant Pages

  • Re: External trust and a member server
    ... I was not sure about that whether this issue is caused by firewall. ... please help me to capture a screen shot of the error ... Restricting Active Directory Replication Traffic to a Specific Port ... External trust and a member server ...
    (microsoft.public.win2000.active_directory)
  • Re: Firewall/VPN
    ... > the ones that are DMZ capable. ... They actually have an extra Port called ... > the D-link regurdless of having as much features or even more seems to ... Most firewall devices can sense an attack ...
    (comp.security.firewalls)
  • Re: OWA connectivity
    ... If you're using PIX on your first firewall and use Checkpoint on ... opened and hosts to which they must be opened between the DMZ and Intranet ... First though I'd like to admit I made a mistake in talking about SMTP port ... Whether or not you use a proxy server in this setup is up to ...
    (microsoft.public.exchange.admin)
  • RE: [fw-wiz] False results to DMZ
    ... The firewall allows anything IP from this scanner. ... > Using NMAP, If I scan one specific DMZ, I only get results with the SYN ... AND it says every port is open. ... Can you post a sanitized version of your PIX config? ...
    (Firewall-Wizards)
  • Re: Dual nic with DMZ via firewall
    ... the WAN NIC to be in our firewalls DMZ. ... email or rww would be protected via DMZ firewall rules. ... If the SBS box is compromised then it also exists on the LAN so maybe ... If you have the SBS server WAN port in the DMZ and your Firewalls LAN is ...
    (microsoft.public.windows.server.sbs)