Domain Controller Behind Firewall
There is a pix firewall behind this router to protect our network.
Domain controller behind firewall. Ad domain controller behind firewall ad domain controller behind firewall mollyking mis op 11 jun 04 09 21. This is good however if your internal firewalls aren t configured properly it can cause all kinds of headache for day to day domain operations. What ports do i need to tell our network people to open to allow for this.
Now i want the pcs in the branch office t. What ports do i need to leave open for the clients. The following information helps you understand the active directory firewall ports you should open from your dmz to your internal network to allow communication from a dmz machine to an internal active directory domain controller.
I want to put an ad domain controller that is running wins and dns behind a firewall. The clients will not be behind the firewall. Icmp is used to determine whether the link is a slow link or a fast link.
You need to open up the appropriate ports to allow this communication from your dmz to domain controllers behind the firewall on your internal network. Kerberos port 88 udp tcp ldap tcp 389 rpc tcp 135. Traffics from win10 172 16 1 200 to ad domain controller 10 10 10 200 traffics from ad domain controller 10 10 10 200 to win10 172 16 1 200 all block.
I have configured a vpn connection between our branch office router and our adsl router. For anyone who has autoenrollment for certificates on machines that are behind firewalls here are the ports and servers you want to look at for setting up firewall rules. I have a domain controller windows 2003 that is behind a cisco firewall.
I have a couple clients that are on a different subnet they have static ips which need to access the dc to authenticate and use shared resources. If you are in a decently secure network your active directory domain controllers are silo d off from all of your workstations and member servers. Hi i want to connect a pc which is out side the firewall to the windows server behind the firewall.