Article ID: 179442
Article Last Modified on 7/31/2007
APPLIES TO
- Microsoft Windows Server 2003, Standard Edition (32-bit x86)
- Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
- Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Professional Edition
- Microsoft Windows NT Server 4.0 Standard Edition
This article was previously published under Q179442
SUMMARY
This article describes how to configure a firewall for
domains and trusts.
MORE INFORMATION
To establish a domain trust or a security channel across a
firewall, the following ports must be opened. Be aware that there may be hosts
functioning with both client and server roles on both sides of the firewall.
Therefore, ports rules may have to be mirrored.
Windows NT
In this environment, one side of the trust is a Windows NT 4.0
trust, or the trust was created by using the NetBIOS names.
| Client Port(s) | Server Port | Service |
|---|
| 137/UDP | 137/UDP | NetBIOS Name |
| 138/UDP | 138/UDP | NetBIOS Netlogon and
Browsing |
| 1024-65535/TCP | 139/TCP | NetBIOS Session |
| 1024-65535/TCP | 42/TCP | WINS Replication |
Windows Server 2003 and Windows 2000 Server
For
a mixed-mode domain that uses either Windows NT domain controllers or legacy
clients, trust relationships
between
Windows Server 2003-based domain
controllers and Windows 2000 Server-based domain
controllers
may necessitate that
all the ports for Windows NT that are listed in the previous table be
opened in addition to the following ports.
Note The two domain controllers are both in the same
forest, or the two domain controllers are both in a separate forest. Also, the trusts in the forest are
Windows 2003 trusts or later version trusts.
| Client Port(s) | Server Port | Service |
|---|
| 1024-65535/TCP | 135/TCP | RPC |
| 1024-65535/TCP | 1024-65535/TCP | LSA RPC
Services (*) |
| 1024-65535/TCP/UDP | 389/TCP/UDP | LDAP |
| 1024-65535/TCP | 636/TCP | LDAP SSL |
| 1024-65535/TCP | 3268/TCP | LDAP GC |
| 1024-65535/TCP | 3269/TCP | LDAP GC SSL |
| 53,1024-65535/TCP/UDP | 53/TCP/UDP | DNS |
| 1024-65535/TCP/UDP | 88/TCP/UDP | Kerberos |
| 1024-65535/TCP | 445/TCP | SMB |
(*) To define RPC server ports that are used by the LSA RPC
services, see the "Domain controllers and Active Directory" section in the
following Microsoft Knowledge Base article:
832017 Service overview and network port requirements for the Windows Server system
For Active Directory to function correctly through a
firewall, the Internet Control Message Protocol (ICMP) protocol must be allowed
through the firewall from the clients to the domain controllers so that the
clients can receive Group Policy information.
ICMP is used to
determine whether the link is a slow link or a fast link. ICMP is a legitimate
protocol that Active Directory uses for Group Policy detection and for Maximum
Transfer Unit (MTU) detection. The Windows Redirector also uses ICMP to verify
that a server IP is resolved by the DNS service before a connection is
made.
If you want to minimize ICMP traffic, you can use the following
sample firewall rule:
<any> ICMP -> DC IP addr = allow
Unlike the TCP protocol layer and the UDP
protocol layer, ICMP does not have a port number. This is because ICMP is
directly hosted by the IP layer.
By default, Windows Server 2003 and Windows 2000
Server DNS servers use ephemeral client-side ports when they query other DNS
servers. However, this behavior may be modified with a specific registry
setting that is described in the following article in the Microsoft Knowledge
Base:
260186 The SendPort DNS registry key does not work as expected
For more information about Active Directory and
firewall configuration, view the "Active Directory in Networks Segmented by
Firewalls" Microsoft White Paper. To do this, visit the following Web site:
Alternatively, you can establish a trust through the
Point-to-Point Tunneling Protocol (PPTP) compulsory tunnel, and this will limit
the number of ports that the firewall will need to open. For PPTP, the
following ports must be enabled.
| Client Ports | Server Port | Protocol |
|---|
| 1024-65535/TCP | 1723/TCP | PPTP |
In addition, you would have to enable IP PROTOCOL 47
(GRE).
Note When you add permissions to a resource on a trusting domain for
users in a trusted domain, there are some differences between the Windows 2000
and Windows NT 4.0 behavior. If the computer cannotdisplay a list of the remote
domain's users:
- Windows NT 4.0 tries to resolve manually-typed names by
contacting the PDC for the remote user's domain (UDP 138). If that
communication fails, a Windows NT 4.0-based computer contacts its own PDC, and
then asks for resolution of the name.
- Windows 2000 and Windows Server 2003 also try to contact
the remote user's PDC for resolution over UDP 138, but they do not rely on
using their own PDC. Make sure that all Windows 2000-based member servers and
Windows Server 2003-based member servers that will be granting access to
resources have UDP 138 connectivity to the remote PDC.
Additional query words: tcpip
Keywords: kbenv kbhowto kbnetwork KB179442