Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Acitve Directory replication through PIX

Status
Not open for further replies.

Donachie

Technical User
Jan 31, 2005
80
GB
Can anyone tell me which ports to open for AD replication through a PIX? Our PIX is an internal firewall subnetting our network. DCs exist on all subnets.

Thanks.
 
great - thanks.

PIX does not do a fixup for rpc does it?
 
fixup doesn't open ports..

fixup filters traffic on those ports.

Computer/Network Technician
CCNA
 
yeah i know that - rpc sets the port it will communicate on in the initial setup . this can be any port between 1024 to 65000. if you could use fixup it would listen in and allow the port to open for this communication - as far as i know.

as fixup dosent work for rpc i will have to either use the registray hack or open up all these ports.
 
the pix does not actively communicate with any systems. the pix only filters traffic that is coming into itself.

since no machine could possibly know what port rpc is running on (before asking), no firewall could know either.

Computer/Network Technician
CCNA
 
Donachie,

You are correct. fixup will dynamically open and close ports as needed for certain protocols such as ftp by inspecting a portion of the packet payload. When one host renogitates a port during a handshake, fixup will adjust. To my knowledge, there is no fixup for rpc. Good luck on the reg hack.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top