Avatar of dano992
 asked on

Port 3268/tcp used for the msft-gc service

is it safe to open up this port in my network
i have 2 vlans
server vlans (where active directory resides)
worksation VLan (users)
im having issues using active directory users and computers tool from my worksation
due to not being able to contact the global catalog server efficiently
all traffic (VLANs) flow through out firewall
if i opened up this port on the firewall so that it was opened between the 2 vlans would solve my issue

do i need to open this both incomming and outgoing?
is it safe to open this port on the firewall between the 2 vlans?
Active DirectoryHardware FirewallsSoftware Firewalls

Avatar of undefined
Last Comment
Sandesh Dubey

8/22/2022 - Mon
Mike Kline

Yes it is safe it is on your internal network and 3268 is how you communicate with a GC, common port that is open and needed if DCs were in different segments/locations(common)   http://technet.microsoft.com/en-us/library/bb727063.aspx


Sandesh Dubey

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question

do i need to open both incoming and outgoing from the worksations vlan?
Sandesh Dubey

You should enable the same on vlan.
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes