Ports to be opened for WAN link.

Hello,

We have a Site-to-Site VPN conneciton between Cisco PIX (remote office) Cisco ASA (main office)
Im setting up the ACL filters for this connection, can someone let me know what ports i need to "allow" for the following services?

What ports are required for:

*Domain clients workstation login.
*DNS
*WINS
*Exchange connection (from outlook clients) - i think there will be a few ports
*Anything else you can think of!

Thanks,

Craig
LVL 3
chouckhamAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

James MontgomeryCommented:
Hello chouckham,

Here is a starter:

http://www.poopoccurs.com/windows/2kports.html

To be honest, setting something like this up is usually more pain than it is worth... for an 'internal' network.

Regards,

JimboEfx
0
chouckhamAuthor Commented:
Thanks,

I was also thinking along the same lines.
I was only considering this for a complete lockdown.

Thanks,
Craig
0
James MontgomeryCommented:
Yeah, I totally see where you are comming from. But the moment something is wrong and needs troubleshooted - you'll turn the lot off to see what the problem is!

There are some cools things you can do... although i'll not pretend to be authoriative here.. just giving you ideas:

port security:
http://tldp.org/HOWTO/html_single/8021X-HOWTO/#what8021x

IPsec as a firewall
http://homepages.wmich.edu/~mchugha/w2kfirewall.htm

Windows PKI
http://technet.microsoft.com/en-gb/library/bb457034.aspx

Windows Access Based Enumeration
http://www.microsoft.com/windowsserver2003/techinfo/overview/abe.mspx

Minasi on Security
http://www.minasi.com/secoutln.htm
The guy is a must listen...

Physical security. Without this you have no security.

HTH
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Databases

From novice to tech pro — start learning today.