• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 153
  • Last Modified:

When adding a domain controller to the domain, is access to server(s) containing all the FSMO roles necessary?

I plan to add a further DC to the domain.  This DC sits behind a firewall so I'll need to have it configured to allow the relevant data across the relevant ports (anyone know what these are?).  Furthermore will the server being dcpromo'd need to speak to all the FSMO role holders?
2 Solutions
The new DC WILL need to contact the existing domain and FSMO role holder and transfer data. See http://blogs.dirteam.com/blogs/carlos/default.aspx for a list of ports required.
Matthew MillersCommented:
If you can allow any/any between the two DCs, it will make like a lot easier for you.
Toni UranjekConsultant/TrainerCommented:

Configuring firewall for replication is always tricky because some RPC ports are dynamically opened. It would be better that you establish site-site VPN channel.

"How to configure a firewall for domains and trusts"


The new generation of project management tools

With monday.com’s project management tool, you can see what everyone on your team is working in a single glance. Its intuitive dashboards are customizable, so you can create systems that work for you.

Ju1ianAuthor Commented:
Thanks guys....  about the FSMO roles... will all role holders need to be contacted?
Toni UranjekConsultant/TrainerCommented:
Aren't all of them on the same server?

If they are not, I will speculate, that Infrastructure Master is not used in process of joining new DC to domain, but I have never actually checked this. All other four roles holders will be contacted.
Ju1ianAuthor Commented:
Thanks KCTS, the link is most informative re ports that are used in this process.  Thanks toniur for the FSMO role answer, I assume the fact that the dcpromo process will converse with a GC that this probably fits with the need not to speak with the Inf master.
Ju1ianAuthor Commented:
toniur... although it's a single domain forest, not all the roles are on a singer server (contrary to MS recommendations for this scenario).  The schema and naming master are on the "root" server with the other 3 roles having been moved to a server at another site.  The dcpromo I'll perform will add a 6th site to the forest.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free tool for managing users' photos in Office 365

Easily upload multiple users’ photos to Office 365. Manage them with an intuitive GUI and use handy built-in cropping and resizing options. Link photos with users based on Azure AD attributes. Free tool!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now