Solved

Client to Domain Controller communication through a firewall

Posted on 2002-05-14
4
1,570 Views
Last Modified: 2013-12-19
Hello,

we have a single active directory domain set up, but some of our clients wil need to communicate with a domain controller that is behind a firewall. I have been reading through the firewall article written by Steve Riley of Microsoft but it is focused purely on DC to DC communication over a firewall. He outlines various options and all the ports that would need to be opened.

Since client to DC communication is less involved, i want to know which of the ports I need to have opened. In particular I want to know if the RPC dynamic assigment is required in this scenario. Are there any other articles other than the one by Steve that summaries what ports are needed in client to DC communications, when a firewall needs to be crossed.

Please advise.

Simon
0
Comment
Question by:schurch122297
4 Comments
 
LVL 9

Accepted Solution

by:
TooKoolKris earned 200 total points
ID: 7011245
RPC Dynamic assignment normally takes place with the ports starting right over the well known i.e. 1025, 1026, 1027 ect.. You may want to leave a few of these open for those. You might have a hard time trying to find any specific articles about what ports need to be left open due to DC communications with other DC's. I would offer the suggestion of getting a port scanner; you can get one for free here - http://www.webattack.com/get/superscan.shtml

Setup your servers as normal and every so often scan the servers for open ports. You would want to do it during anytime the servers are running communications between each other, i.e. zone info, replication, ect..

This isn't the easiest solution obviously but you will learn a lot about what goes on between the servers from a network and transport layer level.

Hope this helps,

TooKoolKris
MCSE+I, CCNA, A+
0
 

Expert Comment

by:CleanupPing
ID: 9160061
schurch:
This old question needs to be finalized -- accept an answer, split points, or get a refund.  For information on your options, please click here-> http:/help/closing.jsp#1
EXPERTS:
Post your closing recommendations!  No comment means you don't care.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
Resolve DNS query failed errors for Exchange
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now