Re: IPSEC through firewall for DC replication

From: Steve Riley [MSFT] (steriley_at_microsoft.com)
Date: 06/06/04


Date: Sat, 5 Jun 2004 19:52:28 -0700

Please see
http://www.microsoft.com/downloads/details.aspx?FamilyID=c2ef3846-43f0-4caf-9767-a9166368434e&displaylang=en.

It's the definitive guide for configuring domain controller replication
across a firewall.

Steve
steriley@microsoft.com

"tony" <anonymous@discussions.microsoft.com> wrote in message
news:178a101c44994$a47f4c50$a601280a@phx.gbl...
> ALL,
>
> I am trying to use IPSEC to send Domain Controller
> replication through the firewall for a one-way trust with
> the Domain controllers in the DMZ. However, IPSec (ESP)
> packet dropped keeps occuring at the firewall because the
> destination port is being randomly assigned, the source
> port for IPSEC(ESP) is port 0. Is there a way to force
> the destination port to a specific port number so I can
> allow it in my firewall rules?
>
> Thank you,
>
> Tony



Relevant Pages

  • Re: sysvol replication breaks when IPSec running between DCs & fir
    ... IPSec" as per as per Steve Riley ... I do not know how to write a firewall rule to ensure that IP ... Riley says you can "Encapsulate domain controller traffic inside ... the IPsec exists underneath the Windows Firewall ...
    (microsoft.public.windows.server.active_directory)
  • Re: sysvol replication breaks when IPSec running between DCs & firewal
    ... Also have a look here about UDP port 500: ... open the firewall for ports required by IPSec, ... We have two root DCs and three child domain DCs. ...
    (microsoft.public.windows.server.active_directory)
  • Re: UDP Port 500 open
    ... I use a free software firewall ... >> I have recently installed a firewall and it says that UDP Port 500 is ... > ISAKMPD uses this port to negotiate IPSec. ... >> perhaps a registry key and/or disabling some service or other in ...
    (comp.security.misc)
  • Re: Windows 2003 Domain Controller (Open Port 593)
    ... I agree that if you configure a firewall to allow any higher level port ... be able to open up a secure channel to the domain controller, ... Replication RPC services to fixed ports, I am here to tell you that the ...
    (microsoft.public.windows.server.security)
  • IPSEC through firewall for DC replication
    ... I am trying to use IPSEC to send Domain Controller ... packet dropped keeps occuring at the firewall because the ... port for IPSECis port 0. ...
    (microsoft.public.win2000.security)

Loading