Servers in two Vlans

chart_at_homesoc.com
Date: 10/26/05


Date: 26 Oct 2005 08:00:32 -0700

Question #1
I have a domain forest in my current WAN. I have been asked to tighen
up security but implementing ACL's between VLAN's. My problem is this.
 I have say office A on VlanA with the main controller and office B on
VlanB with a child controller. What ports am i going to have to open
up between those vlans so the two servers can talk to each other and
keep active directory happy.

Question #2
Would I need to open the same ports say if a workstation was on a
different Vlan then the server it authenticates with. Not sure this
would happen but just wanted to know in the event I run into that.

I have all offices connected via Point to Point T1, switches are all
Cisco 3550's and all servers are compaq DL series of one flavor or
another.

the goal is to open only the ports needed to have the server talk to
each other and keep Active Directory working, allow clients to
authenticate and all that other sever functions and block everything
else



Relevant Pages

  • Re: Servers in two Vlans
    ... A good old Active Directory Replication Across Firewalls whitepaper ... Refer to the "Limited RPC" section for a reasonable port list ... What ports am i going to have to open ... > up between those vlans so the two servers can talk to each other and ...
    (microsoft.public.windows.server.security)
  • Re: Windows 2000 Server pings and scan ports on the network
    ... SysInternals to view what network related processes are running on ... the servers including what ports and application they map to. ... I don'y believe it is Active Directory related.--- Steve ... > Hi we have servers that sometimes ping and scan ports of some PC's. ...
    (microsoft.public.win2000.security)
  • Re: IMPACT of (Delegation Control of Group Policy) on Active Direc
    ... GPOs applied on DCs and Servers ... Health of active Directory and DCs since unSYSTEM Engineer is having ... Actually my MAIN CONCERN is that how would delegating control of Group ... Policy to SUPPORT Engineer affect health of active directory?? ...
    (microsoft.public.windows.server.active_directory)
  • RE: Need Advice (Repost)
    ... configuration there is no preference to the prod DCs over the DR DCs" Is ... if the DR servers are in a different AD site the users will be able to ... Active Directory Sites should be configured in this scenario. ... I've built two Active Directory Domain ...
    (microsoft.public.windows.server.active_directory)
  • Re: Visa PCI Firewall Requirements and Windows Networks
    ... GP without the risk of open ports or a DC in the DMZ. ... Outbound access should be minimized but if windows update is your ... alternative tools on trusted servers to patch your machine. ... > behind the second firewall. ...
    (Focus-Microsoft)