Click here to get back home

clients separated from DC by firewall

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
clients separated from DC by firewall Jay 06-07-2007
Posted by Jay on June 8, 2007, 9:15 am
Please log in for more thread options
Thanks, Svyatoslav

I am aware of the tcp/udp, I was just trying to be brief :)

Just wondering - can this be done in a simpler way? Is Ipsec a better
option?


> What is missing:
>
> * RPC endpoint mapper (135/TCP) + a fixable
> (http://support.microsoft.com/kb/224196/) port for login services
> * LDAP to GC (3268/TCP)
> * ICMP ping
>
> Note that Kerberos is UDP by default and LDAP is using both TCP and UDP
> (UDP = LDAP ping); DNS also may use TCP. Protocols are important. SSL may
> change port requirements, too. See http://support.microsoft.com/kb/832017/
>
> --
> Svyatoslav Pidgorny, MS MVP - Security, MCSE
> -= F1 is the key =-
>
> * http://sl.mvps.org * http://msmvps.com/blogs/sp *
>
>> straightforward question - I have a range of PCs that are separated from
>> their domain controller by a PIX. I need to know what ports are required
>> for me to join these clients to the domain.
>>
>> the doc 'Active Directory in Networks Segmented by Firewalls' leads me to
>> believe I need:
>>
>> 445 (DS)
>> 88 (Kerberos)
>> 389 (LDAP)
>> 53 (DNS)
>>
>> assume both TCP and UDP for the above. The problem is I am getting and
>> RPC error and I see 135 being dropped by my PIX. What are the ports
>> needed to join a computer to a domain?
>>
>> Is there a 'right' way to do this?
>>
>> Thanks
>> Blake
>
>


Posted by S. Pidgorny on June 8, 2007, 11:35 pm
Please log in for more thread options
G'day:

> Thanks, Svyatoslav
>
> I am aware of the tcp/udp, I was just trying to be brief :)
>
> Just wondering - can this be done in a simpler way? Is Ipsec a better
> option?

Better in what way?

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *



Posted by Jay on June 11, 2007, 9:38 am
Please log in for more thread options
could I just pass IPSEC through my firewall and then tunnel these packets
via IPSEC?

I could be reading the docs wrong...


> G'day:
>
>> Thanks, Svyatoslav
>>
>> I am aware of the tcp/udp, I was just trying to be brief :)
>>
>> Just wondering - can this be done in a simpler way? Is Ipsec a better
>> option?
>
> Better in what way?
>
> --
> Svyatoslav Pidgorny, MS MVP - Security, MCSE
> -= F1 is the key =-
>
> * http://sl.mvps.org * http://msmvps.com/blogs/sp *
>
>


Posted by S. Pidgorny on June 12, 2007, 3:34 am
Please log in for more thread options
You may... The difference is that between a lot of portocols capable of
carrying all user information and files, and anything at all.

In other words - if you think that IPsec though a firewall is a right
solution then you don't need the firewall.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

> could I just pass IPSEC through my firewall and then tunnel these packets
> via IPSEC?
>
> I could be reading the docs wrong...
>
>
>> G'day:
>>
>>> Thanks, Svyatoslav
>>>
>>> I am aware of the tcp/udp, I was just trying to be brief :)
>>>
>>> Just wondering - can this be done in a simpler way? Is Ipsec a better
>>> option?
>>
>> Better in what way?
>>
>> --
>> Svyatoslav Pidgorny, MS MVP - Security, MCSE
>> -= F1 is the key =-
>>
>> * http://sl.mvps.org * http://msmvps.com/blogs/sp *
>>
>>
>



Similar ThreadsPosted
Radius with dynamic dns clients September 25, 2008, 4:14 pm
Different IIS 5 & IIS 6 behavior on checking clients' certificates September 5, 2005, 11:55 pm
IIS 6 behavior on checking clients' certificates (again) September 16, 2005, 4:47 am
IIS 6 behavior on checking clients' certificates (again 2) September 29, 2005, 12:40 am
Auto-renewing certs w/ VPN clients February 15, 2006, 9:44 am
Win2003 Server automated password changes. What about Mac clients March 7, 2008, 12:32 pm
vista domain clients no longer see USB drives June 9, 2008, 7:05 pm
server 2000 Group policy for windows xp clients January 18, 2006, 9:59 pm
PKI User certificate auto-enrollment for XP clients not logging onto domain computer May 18, 2007, 11:02 am
Failure audits for object access on logon scripts and startup scripts, but clients still run them fine. February 27, 2008, 7:40 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap