Skip to content
View in the app

A better way to browse. Learn more.

MSFN

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

which ports should I open to allow active directory service?

Featured Replies

As title, I am currently use Win server 2003 as my domain DC. I want to open the windows embeded firewall, however, I don't know which ports I must open. If I don't open any ports additionally, computers in my domain cannot login. Does anyone know which ports I must open?

It is strongly recommended that you do NOT use a host firewall on a Domain Controller - leave that job to perimeter firewalls.

The list of ports for various types of traffic is quite extensive and varies depending on which roles the server has - also Remote Procedure Call design means the dynamic port range requirement punches a massive hole in the list of ports to let replication (amongst other things) work.

If you are hell-bent on trying to run the Windows Firewall service on a DC then here are some KBs you should look at:

"Service overview and network port requirements for the Windows Server system"

http://support.microsoft.com/?id=832017

"Restricting Active Directory replication traffic to a specific port"

http://support.microsoft.com/?id=224196

"How to restrict FRS replication traffic to a specific static port"

http://support.microsoft.com/?id=319553

"How to troubleshoot RPC Endpoint Mapper errors"

http://support.microsoft.com/?id=839880

Again, it's really not recommended to even put a firewall between DCs if possible, and certainly not using the host firewall service.

It is strongly recommended that you do NOT use a host firewall on a Domain Controller - leave that job to perimeter firewalls.

Hehe, tell me about it! I was running a software firewall on my server at work (AD server, DNS server, DHCP server, File server, Print server), lots of things didn't work. Eventually managed to get a Pentium 2 pc and shoved it between the server and the DSL modem to act as a firewall. Took a bit of time to convince the boss though... :lol:

Edited by nitroshift

Mr Snrub, nice post! Very informative. Have you ever attempted this?

-John

Mr Snrub, nice post! Very informative. Have you ever attempted this?
Nope, I've only helped people clean up the mess after they have tried it, and answered these kinds of advisory cases before.

Firewalls (perimeter as well has host) can cause a lot of issues that aren't immediately obvious, and only by taking simultaneous network traces at both ends can you see what data is getting dropped or munged - and sometimes it's not just packet filters but the "smart defense"modules which are inspecting the payloads of the packets and blocking them based on a rigid set of rules.

Create an account or sign in to comment

Recently Browsing 0

  • No registered users viewing this page.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.