sonuteklists
Technical User
I found the following information in the Microsoft website regadring replication over the firewall which asked me to configure the firewall to permit the following,
Service Port/protocol
RPC endpoint mapper 135/tcp, 135/udp
NetBIOS name service 137/tcp, 137/udp
NetBIOS datagram service 138/udp
NetBIOS session service 139/tcp
RPC static port for AD
replication <fixed-port>/tcp
SMB over IP (Microsoft-DS) 445/tcp, 445/udp
LDAP 389/tcp
LDAP over SSL 636/tcp
Global catalog LDAP 3268/tcp
Global catalog LDAP over SSL 3269/tcp
Kerberos 88/tcp, 88/udp
DNS 53/tcp, 53/udp
WINS resolution (if required) 1512/tcp, 1512/udp
WINS replication (if required) 42/tcp, 42/udp
What I have to do is this,
My AD is inside a firewall. I have to let an outside application access the AD over the SECURE CHANNEL only. So,
- if I open only 636/tcp, will that be enough ??
- what other ports will I need to open, like kerberos, etc ??
- Do I have to do something to enable "LDAP over SSL" in AD ??
Again, all the application from outside the firewall has to do is to get the authentication and authorization details from the AD inside the firewall over a SECURE CHANNEL only !!
Thanks.
Service Port/protocol
RPC endpoint mapper 135/tcp, 135/udp
NetBIOS name service 137/tcp, 137/udp
NetBIOS datagram service 138/udp
NetBIOS session service 139/tcp
RPC static port for AD
replication <fixed-port>/tcp
SMB over IP (Microsoft-DS) 445/tcp, 445/udp
LDAP 389/tcp
LDAP over SSL 636/tcp
Global catalog LDAP 3268/tcp
Global catalog LDAP over SSL 3269/tcp
Kerberos 88/tcp, 88/udp
DNS 53/tcp, 53/udp
WINS resolution (if required) 1512/tcp, 1512/udp
WINS replication (if required) 42/tcp, 42/udp
What I have to do is this,
My AD is inside a firewall. I have to let an outside application access the AD over the SECURE CHANNEL only. So,
- if I open only 636/tcp, will that be enough ??
- what other ports will I need to open, like kerberos, etc ??
- Do I have to do something to enable "LDAP over SSL" in AD ??
Again, all the application from outside the firewall has to do is to get the authentication and authorization details from the AD inside the firewall over a SECURE CHANNEL only !!
Thanks.