IPSEC through firewall for DC replication

From: tony (anonymous_at_discussions.microsoft.com)
Date: 06/03/04


Date: Thu, 3 Jun 2004 11:00:23 -0700

ALL,

I am trying to use IPSEC to send Domain Controller
replication through the firewall for a one-way trust with
the Domain controllers in the DMZ. However, IPSec (ESP)
packet dropped keeps occuring at the firewall because the
destination port is being randomly assigned, the source
port for IPSEC(ESP) is port 0. Is there a way to force
the destination port to a specific port number so I can
allow it in my firewall rules?

Thank you,

Tony



Relevant Pages

  • Re: sysvol replication breaks when IPSec running between DCs & fir
    ... IPSec" as per as per Steve Riley ... I do not know how to write a firewall rule to ensure that IP ... Riley says you can "Encapsulate domain controller traffic inside ... the IPsec exists underneath the Windows Firewall ...
    (microsoft.public.windows.server.active_directory)
  • Re: sysvol replication breaks when IPSec running between DCs & firewal
    ... Also have a look here about UDP port 500: ... open the firewall for ports required by IPSec, ... We have two root DCs and three child domain DCs. ...
    (microsoft.public.windows.server.active_directory)
  • Re: UDP Port 500 open
    ... I use a free software firewall ... >> I have recently installed a firewall and it says that UDP Port 500 is ... > ISAKMPD uses this port to negotiate IPSec. ... >> perhaps a registry key and/or disabling some service or other in ...
    (comp.security.misc)
  • Re: Windows 2003 Domain Controller (Open Port 593)
    ... I agree that if you configure a firewall to allow any higher level port ... be able to open up a secure channel to the domain controller, ... Replication RPC services to fixed ports, I am here to tell you that the ...
    (microsoft.public.windows.server.security)
  • AD Replication through IPSEC
    ... I am trying to use IPSEC to send Domain Controller ... packet dropped keeps occuring at the firewall because the ... port for IPSECis port 0. ...
    (microsoft.public.win2000.active_directory)

Loading