When adding a domain controller to the domain, is access to server(s) containing all the FSMO roles necessary?

I plan to add a further DC to the domain.  This DC sits behind a firewall so I'll need to have it configured to allow the relevant data across the relevant ports (anyone know what these are?).  Furthermore will the server being dcpromo'd need to speak to all the FSMO role holders?
Ju1ianAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Brian PiercePhotographerCommented:
The new DC WILL need to contact the existing domain and FSMO role holder and transfer data. See http://blogs.dirteam.com/blogs/carlos/default.aspx for a list of ports required.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Matthew MillersCommented:
If you can allow any/any between the two DCs, it will make like a lot easier for you.
0
Toni UranjekConsultant/TrainerCommented:
Hi!

Configuring firewall for replication is always tricky because some RPC ports are dynamically opened. It would be better that you establish site-site VPN channel.

"How to configure a firewall for domains and trusts"
http://support.microsoft.com/kb/179442

HTH

Toni
0
Big Business Goals? Which KPIs Will Help You

The most successful MSPs rely on metrics – known as key performance indicators (KPIs) – for making informed decisions that help their businesses thrive, rather than just survive. This eBook provides an overview of the most important KPIs used by top MSPs.

Ju1ianAuthor Commented:
Thanks guys....  about the FSMO roles... will all role holders need to be contacted?
0
Toni UranjekConsultant/TrainerCommented:
Aren't all of them on the same server?

If they are not, I will speculate, that Infrastructure Master is not used in process of joining new DC to domain, but I have never actually checked this. All other four roles holders will be contacted.
0
Ju1ianAuthor Commented:
Thanks KCTS, the link is most informative re ports that are used in this process.  Thanks toniur for the FSMO role answer, I assume the fact that the dcpromo process will converse with a GC that this probably fits with the need not to speak with the Inf master.
0
Ju1ianAuthor Commented:
toniur... although it's a single domain forest, not all the roles are on a singer server (contrary to MS recommendations for this scenario).  The schema and naming master are on the "root" server with the other 3 roles having been moved to a server at another site.  The dcpromo I'll perform will add a 6th site to the forest.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Microsoft Server OS

From novice to tech pro — start learning today.