Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , ,

Sponsored Links



Domain Controller - Firewall Ports

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 10-08-2009
Soregg
 
Posts: n/a
Domain Controller - Firewall Ports

Hi folks,

Would anyone give me some reference/ideas on firewall ports for DCs/PCs
between offices please? I configured [DC <-any-> any DC] between offices,
[PC<-block->remote offices] and well configured the ADSS (Mapped DC &
Subnets to related site). However I found that PC usually go to found other
DCs. I really have no idea on that and I cannot simulate the case V.V

Thank you very much in advance.

Cheers, Soregg

Reply With Quote
  #2  
Old 10-08-2009
Santhosh Sivarajan
 
Posts: n/a
Re: Domain Controller - Firewall Ports

Take a look at these articles for DC to DC communication through a firewall:

http://support.microsoft.com/kb/555381
http://support.microsoft.com/?kbid=179442
http://support.microsoft.com/?kbid=154596

Also, make sure you have proper AD site and subnet configuration. Client
will look for a local DCs inside the same site based on your subnet
configuration inside AD sites and services.

--
Santhosh Sivarajan | MCTS, MCSE (W2K3/W2K/NT4), MCSA (W2K3/W2K/MSG), CCNA
Houston, TX
http://blogcastrepository.com/blogs/santhosh/
http://www.sivarajan.com/publications.html


"Soregg" <se@soregg.com> wrote in message
news:685B88A2-473B-4A46-B864-A24B2A35BD14@microsoft.com...
> Hi folks,
>
> Would anyone give me some reference/ideas on firewall ports for DCs/PCs
> between offices please? I configured [DC <-any-> any DC] between offices,
> [PC<-block->remote offices] and well configured the ADSS (Mapped DC &
> Subnets to related site). However I found that PC usually go to found
> other DCs. I really have no idea on that and I cannot simulate the case
> V.V
>
> Thank you very much in advance.
>
> Cheers, Soregg


Reply With Quote
  #3  
Old 10-08-2009
Ace Fekay [MCT]
 
Posts: n/a
Re: Domain Controller - Firewall Ports

"Soregg" <se@soregg.com> wrote in message
news:685B88A2-473B-4A46-B864-A24B2A35BD14@microsoft.com...
> Hi folks,
>
> Would anyone give me some reference/ideas on firewall ports for DCs/PCs
> between offices please? I configured [DC <-any-> any DC] between offices,
> [PC<-block->remote offices] and well configured the ADSS (Mapped DC &
> Subnets to related site). However I found that PC usually go to found
> other DCs. I really have no idea on that and I cannot simulate the case
> V.V
>
> Thank you very much in advance.
>
> Cheers, Soregg



I agree with Santosh that it's a Sites configuration, or more than likely, a
lack of configuring Sites. Sites control client logon traffic to DCs and GCs
within their Sites, as well as replication traffic between DCs.

Based on what you posted, this is not a firewall issue from your
description. As long as any-any is open, you have no problems. If Cisco,
make sure DNS protocol fixup 1280 is set, or if any other firewall, make
sure EDNS0 option is allowed. Consult your docs.

Configure Site Settings: Active Directory
Jan 21, 2005 ... Configure site settings. Create a site · Rename a site ·
Delete a site · Create a subnet · Associate a subnet with a site ...
http://technet.microsoft.com/en-us/l...55(WS.10).aspx

Managing Sites
Jan 6, 2003 ... Managing sites in Active Directory involves adding new
subnet, site, and site link objects when the network grows, as well as
configuring a ...
http://technet.microsoft.com/en-us/l.../bb727051.aspx

---
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Please reply back to the newsgroup or forum to benefit from collaboration
among responding engineers, and to help others benefit from your resolution.

Ace Fekay, MCT, MCTS Exchange, MCSE, MCSA 2003 & 2000, MCSA Messaging
Microsoft Certified Trainer

For urgent issues, please contact Microsoft PSS directly. Please check
http://support.microsoft.com for regional support phone numbers.

Reply With Quote
  #4  
Old 10-08-2009
Soregg
 
Posts: n/a
Re: Domain Controller - Firewall Ports

Many thanks for info from Santhosh & Ace, I will study it and discuss
afterward in need.
Cheers, Alex

"Soregg" <se@soregg.com> wrote in message
news:685B88A2-473B-4A46-B864-A24B2A35BD14@microsoft.com...
> Hi folks,
>
> Would anyone give me some reference/ideas on firewall ports for DCs/PCs
> between offices please? I configured [DC <-any-> any DC] between offices,
> [PC<-block->remote offices] and well configured the ADSS (Mapped DC &
> Subnets to related site). However I found that PC usually go to found
> other DCs. I really have no idea on that and I cannot simulate the case
> V.V
>
> Thank you very much in advance.
>
> Cheers, Soregg


Reply With Quote
  #5  
Old 10-08-2009
Ace Fekay [MCT]
 
Posts: n/a
Re: Domain Controller - Firewall Ports

"Soregg" <se@soregg.com> wrote in message
news:0518E4E9-6E47-4E91-924D-3060490C79BB@microsoft.com...
> Many thanks for info from Santhosh & Ace, I will study it and discuss
> afterward in need.
> Cheers, Alex


You are welcome. Post back if you have any specific questions. That's why
we're here!

Ace

Reply With Quote
  #6  
Old 10-08-2009
Soregg
 
Posts: n/a
Re: Domain Controller - Firewall Ports

Thanks a lot!
Alex

"Ace Fekay [MCT]" <aceman@mvps.RemoveThisPart.org> wrote in message
news:OOHx0tWGKHA.2376@TK2MSFTNGP03.phx.gbl...
> "Soregg" <se@soregg.com> wrote in message
> news:0518E4E9-6E47-4E91-924D-3060490C79BB@microsoft.com...
>> Many thanks for info from Santhosh & Ace, I will study it and discuss
>> afterward in need.
>> Cheers, Alex

>
> You are welcome. Post back if you have any specific questions. That's why
> we're here!
>
> Ace


Reply With Quote
  #7  
Old 10-08-2009
Paul Bergson [MVP-DS]
 
Posts: n/a
Re: Domain Controller - Firewall Ports

Review the KB link below. It will out line the client ports required, by
the o/s type:
http://support.microsoft.com/kb/179442/en-us


--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4
Microsoft's Thrive IT Pro of the Month - June 2009

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.

"Soregg" <se@soregg.com> wrote in message
news:685B88A2-473B-4A46-B864-A24B2A35BD14@microsoft.com...
> Hi folks,
>
> Would anyone give me some reference/ideas on firewall ports for DCs/PCs
> between offices please? I configured [DC <-any-> any DC] between offices,
> [PC<-block->remote offices] and well configured the ADSS (Mapped DC &
> Subnets to related site). However I found that PC usually go to found
> other DCs. I really have no idea on that and I cannot simulate the case
> V.V
>
> Thank you very much in advance.
>
> Cheers, Soregg



Reply With Quote
  #8  
Old 20-08-2009
Ace Fekay [MCT]
 
Posts: n/a
Re: Domain Controller - Firewall Ports

Soregg expressed precisely :
> Thanks a lot!
> Alex
>


You are welcome!

Ace


Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Domain Controller - Firewall Ports"
Thread Thread Starter Forum Replies Last Post
question about domain trusts and firewall ports Adam Sandler Active Directory 6 17-08-2010 06:37 PM
Firewall Ports Carl Active Directory 3 15-10-2009 04:54 PM
When you run Dcpromo.exe on Windows 2008 to create a replica domain controller, you receive a message "The operation failed because: A domain controller could not be contacted ... "Access is denied." John Wu Active Directory 4 15-05-2009 12:48 PM
Server 2008 with Hyper-V - domain controller - Firewall GUI's show firewall ON, but netsh reports firewall OFF Bruce Sanderson Windows Server Help 6 07-10-2008 04:27 PM
howto promote additional domain controller to domain controller anisetti.sureshbabu@gmail.com Window 2000 Help 4 11-04-2007 10:19 PM


All times are GMT +5.5. The time now is 08:09 PM.