Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Firewall configuration for Domain controller communication?

Posted on 2011-02-14
3
Medium Priority
?
677 Views
Last Modified: 2012-05-11
I've created a box to serve as my production domain controller at my data centre. The primary DCs sit at the office.

There is a VPN between the two locations and they sit on different subnets.

What modifications do I need to make to my new box's config to let it see the primary DC, and what firewall ports need opening to support full AD replication?
0
Comment
Question by:Borgs8472
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 6

Expert Comment

by:Ryan Smith
ID: 34890364
If you have a vpn setup between the two sites it's safe to open all ports on the vpn policy.  You should probably use vpn encryption though.
0
 
LVL 58

Accepted Solution

by:
tigermatt earned 2000 total points
ID: 34891184

You have a number of options available to you:
Open all ports across the VPN link as previously suggested.
A quick and dirty fix, but also an insecure one. You should definitely use a high encryption connection between the two offices otherwise all your AD traffic is passing over the Internet in plain text, which is not secure. This also means that your data center servers could fairly easily be attacked on any weak / unpatched port, because all ports are allowed through the firewall.
Configure the server to use set RPC ports for Active Directory communications and then restrict the firewall to only allow the necessary ports.
Much more secure, a much smaller attack surface and you have complete control over what traffic passes between the two sites. It takes some additional time to plan, configure and document your AD setup using this method, but this is a more secure configuration and the one I prefer.

A document available at Microsoft explains in a lot more detail all the ports you need to open for the latter option and the registry changes required to fix the RPC ports at a particular value.
See http://technet.microsoft.com/en-us/library/bb727063.aspx for details.

Don't forget to set up Active Directory Sites and Services for the data center to ensure your DC situated there isn't contacted when the DCs at your main site are available.

-Matt
0
 
LVL 4

Author Closing Comment

by:Borgs8472
ID: 34937106
<3
0

Featured Post

Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
Here's a look at newsworthy articles and community happenings during the last month.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question