Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

DMZ Firewall Ports

Status
Not open for further replies.

micon55

MIS
Feb 22, 2001
74
GB
Hi there.
Am trying to configure my front end server in dmz to communicate across our PIX Firewall.
We have tested the front end inside the firewall and it worked well. Unfortunately, when this server is placed in the dmz, we receive a netlogon error 5719.
I've opened the following ports on the firewall for domain communication, and was wondering if we've missed anything.
135, 88, 389, 445, 3268, domain host and a number above 1024 for endpoint mapping.
Have also configured our GC servers registry for this endpoint TCP/IP entry. Still no joy when logging onto domain.

Any ideas greatly received.
Thanks.
 
Well,

1. The front end needs to talk to DNS on the internal network to resolve the srv records.
2. You'll have some smtp issues if you don't open 691
3. The fromtend needs 80 open to talk to the back end.
4. Open ICMP between the frontend and backend or disable wLDAP ping.

 
Thanks for the reply. Am now exploring other possibilities such as ISA server. Could not get it working.
Thanks again for the response.

Mike
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top