Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: ,

Sponsored Links



Authentication Ports

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 08-05-2009
Mitch
 
Posts: n/a
Authentication Ports

Hi,
I am setting up a point to point T1 in addition to an IPSec tunnel between 2
offices. In order for everything to communicate with the equipment were
using, I will need the port# for exchange email, system traffic and the port
which Active Directory uses to authenticate users. Does anyone know the
answer to this? Thanks.

Mitch
Reply With Quote
  #2  
Old 08-05-2009
Ace Fekay [Microsoft Certified Trainer]
 
Posts: n/a
Re: Authentication Ports

"Mitch" <Mitch@discussions.microsoft.com> wrote in message
news:23FA4A82-0F3B-4364-A7DE-F1F1BB188263@microsoft.com...
> Hi,
> I am setting up a point to point T1 in addition to an IPSec tunnel between
> 2
> offices. In order for everything to communicate with the equipment were
> using, I will need the port# for exchange email, system traffic and the
> port
> which Active Directory uses to authenticate users. Does anyone know the
> answer to this? Thanks.
>
> Mitch



You are better off just opening the VPN wide open between the locations. The
VPN will secure the traffic anyway, so no worries.

Otherwise you must open up a slew of ports to the point it swiss-cheeses the
firewall. In addition the Default emepheral ports need to be opened. They
are the random service ports that Windows uses to communicate, and are
required by AD. They are UDP 1024 - 65535 (See KB179442), but for Vista and
Windows 2008 it's different. Their default start port is UDP 49152, and the
default end port is UDP 65535 (see KB899148).

Have a read on the following:

==================================================================================================== ==
==================================================================================================== ==

Active Directory Firewall ports

Active Directory Replication over FirewallsJan 31, 2006. Active Directory
relies on remote procedure call (RPC)
http://technet.microsoft.com/en-us/l.../bb727063.aspx

How to configure a firewall for domains and trusts
http://support.microsoft.com/?id=179442

Configuring an Intranet Firewall, Apr 14, 2006. Protocol ports required for
the intranet firewall.
Ports required for Active Directory and Kerberos communications
http://technet.microsoft.com/en-us/l.../bb125069.aspx

Active Directory and Firewall PortsI found it hard to find a definitive list
on the internet for what ports needed opening for Active Directory to
replication between Firewalls. ...
http://geekswithblogs.net/TSCustomis...09/112357.aspx




--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSA Messaging, MCT
Microsoft Certified Trainer
aceman@mvps.RemoveThisPart.org

For urgent issues, you may want to contact Microsoft PSS directly. Please
check http://support.microsoft.com for regional support phone numbers.

"Efficiency is doing things right; effectiveness is doing the right
things." - Peter F. Drucker
http://twitter.com/acefekay

Reply With Quote
  #3  
Old 08-05-2009
Phillip Windell
 
Posts: n/a
Re: Authentication Ports

You'd be better off to just decide what you don't want to allow and create
explicit "Deny based" rules for those. Then what isn't explicitly denied
you will allow with a global Allow Rule that follows the Deny Rules. But it
won't be much because every juicy protocol a hacker would ever want to sink
his teeth into you would have allowed it.

I'd to the same as Ace. Just forget filtering completely,..there is
"nothing left" to make it worth the trouble. The IPSec VPN, by definition,
is already a secured connection.


--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------


"Mitch" <Mitch@discussions.microsoft.com> wrote in message
news:23FA4A82-0F3B-4364-A7DE-F1F1BB188263@microsoft.com...
> Hi,
> I am setting up a point to point T1 in addition to an IPSec tunnel between
> 2
> offices. In order for everything to communicate with the equipment were
> using, I will need the port# for exchange email, system traffic and the
> port
> which Active Directory uses to authenticate users. Does anyone know the
> answer to this? Thanks.
>
> Mitch



Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Authentication Ports"
Thread Thread Starter Forum Replies Last Post
USB ports and Mobo USB ports on PC Case Eta!! Motherboard Processor & RAM 7 12-09-2011 11:34 PM
mixing * ports and non-* ports with a NameVirtualHost address is not supported, proceeding with undefined results _Gentoo_Nile_ Operating Systems 3 20-08-2009 11:46 PM
how to forward ports to different internal ports Abshir Networking & Security 2 30-06-2009 11:26 PM
AD Authentication on a DMZ ? Eric Active Directory 8 04-04-2009 03:46 AM
Serial Ports, Com Ports and USB Phil Vista Hardware Devices 7 28-01-2009 05:33 PM


All times are GMT +5.5. The time now is 05:11 PM.