+ Post New Thread
Results 1 to 4 of 4
Windows Server 2000/2003 Thread, Firewall on DCs in Technical; What ports and program exceptions do I need to give on a Domain Controller so that I can have Windows ...
  1. #1

    Join Date
    Jun 2008
    Posts
    719
    Thank Post
    118
    Thanked 64 Times in 52 Posts
    Rep Power
    31

    Firewall on DCs

    What ports and program exceptions do I need to give on a Domain Controller so that I can have Windows Firewall enabled?

    So far I have the following:

    Programs
    C:\WINDOWS\system32\lsass.exe (Local Security Authenication Server)
    C:\WINDOWS\system32\ntfrs.exe (File Replication Service)



    Ports
    123 udp (NTP)
    3268 tcp (Global Catalog LDAP)
    389 tcp & udp (LDAP)
    53 tcp & udp (DNS)
    88 tcp & udp (Kerberos)
    464 tcp & udp (Kerberos Set Password Protocol)

    Do you have any other ports and programs that need exceptions? Just for the record, we don't have an Exchange server hosted internally at school. We get this from an external company.



    In addition to the above, I have a SIMS server and the following program exceptions I have given so far are:

    C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (SQL Server Browser Service)
    C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (SQL Server 2005)

    Is there anything else that's missing?

  2. #2

    Join Date
    Jun 2008
    Posts
    719
    Thank Post
    118
    Thanked 64 Times in 52 Posts
    Rep Power
    31
    *Bump*

  3. #3

    localzuk's Avatar
    Join Date
    Dec 2006
    Location
    Minehead
    Posts
    17,836
    Thank Post
    517
    Thanked 2,478 Times in 1,921 Posts
    Blog Entries
    24
    Rep Power
    837
    Last edited by localzuk; 27th July 2009 at 10:45 AM.

  4. #4

    Join Date
    Mar 2009
    Posts
    27
    Thank Post
    0
    Thanked 2 Times in 2 Posts
    Rep Power
    12
    I'm not completely sure but I believe at least these and more

    UDP 53 - DNS Services

    UDP 67 - DHCP

    UDP 123 - Windows Time Service

    TCP 135 - Remote Procedure Call (RPC)

    UDP 137 - NetBIOS Name Resolution

    UDP 138 - NetBIOS Datagram Service

    TCP 139 - NetBIOS Session Service

    TCP 389 and UDP 389 - LDAP Service

    TCP 445 - Server Message Blocks (SMB)

    TCP 1433 - Microsoft SQL over TCP

SHARE:
+ Post New Thread

Similar Threads

  1. DNS setting on DCs
    By OverWorked in forum Windows
    Replies: 9
    Last Post: 23rd July 2008, 10:16 AM
  2. DCs on VMWare Server guests
    By Norphy in forum Thin Client and Virtual Machines
    Replies: 3
    Last Post: 6th February 2007, 12:35 PM
  3. what is the ratio for DCs to PCs
    By timbo343 in forum Windows
    Replies: 6
    Last Post: 3rd January 2007, 05:16 PM
  4. Replies: 28
    Last Post: 28th November 2006, 03:32 PM
  5. replicationprob with old off 2k DCs
    By browolf in forum Windows
    Replies: 2
    Last Post: 18th October 2006, 11:06 AM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •