Domain Controller Ports
For more information about the dynamic port range change in windows server 2012 and windows server 2012 r2 see.
Domain controller ports. Tcp port 3268 and 3269 are required for global catalog communication from clients to domain controllers. As an example when a client computer tries to find a domain controller it always sends a dns query over port 53 to find the name of the domain controller in the domain. Both dns tcp and udp 53 network ports are used by clients and domain controllers for name resolution purposes.
The netlogon and ntds ports which are part of the dynamic port range unless you use. Tcp port 3268 and 3269 for global catalog from client to domain controller. Domain controllers and client computers required some ports for communicating with each other.
Additionally unless a tunneling protocol is used to encapsulate traffic to active directory a range of ephemeral tcp ports between 1024 to 5000 and 49152 to 65535 are required. Udp port 389 for ldap to handle normal queries from client computers to the domain controllers. Required ports to communicate with domain controller this article discusses the required network ports protocols and services that are used by microsoft client and server operating systems server based programs and their subcomponents in the microsoft windows server system.
Tcp and udp port 445 file replication service. Global catalog servers help in finding an object in the active directory quickly. Tcp port 139 and udp 138 for file replication service between domain controllers.
As a bonus for this post here is a nice poster for you to dream about that. Tcp and udp port 53 for dns from client to domain controller and domain controller to domain controller. Domain controllers client computers and application servers require network connectivity to active directory over specific hard coded ports.
Tcp and udp port 464 kerberos password change. Tcp port 3268 and 3269 global catalog from client to domain controller. Iin addition to domain controller firewall ports you may need a list of member server firewall ports as in that case there are less ports to open.