Netman66,
I went to the Default Domain Controller Security Settings but there is a lot in there. Can you specifically direct me where to find this and how to implement this?
Thanks
Main Topics
Browse All TopicsHello experts,
I have 2 windows 2003 Domain controllers for our domain - both firewalled with windows firewall. I have searched the internet (including this site) to find the proper list of ports to open to allow my network to function properly and I am having the following problems:
With the firewalls enabled - I can't add a new user to the domain or, add a new computer to the domain. If i disable the firewall for a few minutes I can do this. I am also getting errors with the AD replication. If I leave the firewalls off for several hours - AD replication succeeds. Obviously, this is not a secure method and I would like to set this up to work properly.
Here are the ports i have opened:
389 tcp & udp
445 tcp & udp
636 udp
53 tcp & udp
139 tcp
137 tcp & udp
138 udp
3269 tcp
3268 tcp
88 tcp & udp
135 tcp & udp
Am I missing anything?
Can anyone give me a specific list of proper settings. Please be as specific as possible and as detailed as possible.
Thank You...
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
OK...
Computer Config>Admin Templates>Network>Network Connections>Windows Firewall>Domain Profile
You'll need to set these options:
Protect all network connections=Enabled
Allow Remote Admin exceptions=Enabled
Allow File and Print Sharing Exeptions=Enabled
Allow Remote Desktop Exception=Enabled.
You may also need to add a few ports to the exception list in there too. Here is a list of require ports for domain communication, add whatever isn't covered by the above exceptions.
http://support.microsoft.c
Let me know how you make out.
Business Accounts
Answer for Membership
by: Netman66Posted on 2006-01-11 at 06:54:39ID: 15670905
If you look at the Default Domain Controller Policy, there should be new settings under Computer Configuration for the firewall. If memory serves me, there is a Standard profile and Domain Profile to select from. The Domain Profile should already be preset to allow Domain communication to succeed.
If you set this policy then you should not have to manually add the correct ports.
Let me know what you find out.