Domain Controller Firewall Ports
For example when a client computer needs to authenticate it connects to a server which hosts kdc service and which is listening on the port 88.
Domain controller firewall ports. As an example when a client computer tries to find a domain controller it always sends a dns query over port 53 to find the name of the domain controller in the domain. Required ports to communicate with domain controller this article discusses the required network ports protocols and services that are used by microsoft client and server operating systems server based programs and their subcomponents in the microsoft windows server system. Complete list of ports used by domain controllers on active directory firewall ports let s try to make this simple active directory autositecoverage mikileak info on the dc locator process the logon process controlling which dc responds in an ad site and srv records.
This is the default dynamic range for rpc connections. Active directory using several ports to communication between domain controllers to clients. For more information about how to customize this port see domain controllers and active directory in the references section.
This section also includes remote wmi and dcom communications first used in windows server 2012 domain controller promotion during prerequisite validation and with the server manager tool. Therefore you must increase the rpc port range in your firewalls. Windows firewall rules for domain controllers.
These ports are required by both client computers and domain controllers. Most subnets can talk over some ports to a management lan but most subnets are isolated from each other. Windows server 2008 and later versions.
An active directory domain controller needs to listen on specific ports to service different client requests. Currently i have a number of older windows domains scattered throughout the subnets each providing ad to their own little fiefdom independant of each other. Windows server 2008 newer versions of windows server have increased the dynamic client port range for outgoing connections.
That was the list i found at my first referenced url. Tcp port range 1025 5000 if your network has any server 2003 r2 or older domain controllers. The firewall ports will be opened one by one from 172 16 1 0 24 to 10 10 10 0 24 to verify the actual ports required firewall ports required to join ad domain minimum windows 10 client can join to windows 2019 ad domain with the following ports allow in firewall.