Inter-Forest Firewall Ports
hi,
we setting separate forest in dmz; , have 1 in intranet - 2-way (selective auth) trust between them.
what ports need opened on firewall between dmz ad , intranet ad? far thinking of following:
- ldap (389)
- smb (445)
- kerberos (88)
- dns (53)
i did read on http://isc.sans.org/diary.html?storyid=7468 that once trust established, need keep kerberos (88) open on firewall.
could please confirm this, thank you.
tz
we setting separate forest in dmz; , have 1 in intranet - 2-way (selective auth) trust between them.
what ports need opened on firewall between dmz ad , intranet ad? far thinking of following:
- ldap (389)
- smb (445)
- kerberos (88)
- dns (53)
i did read on http://isc.sans.org/diary.html?storyid=7468 that once trust established, need keep kerberos (88) open on firewall.
could please confirm this, thank you.
tz
ultimately depends on goal. assume goes beyond establishing trust relationship. you should consult http://support.microsoft.com/kb/832017 to identify specific requirements corresponding functionality want make available...
considering circumstances, might want consider using ipsec instead...
hth
marcin
considering circumstances, might want consider using ipsec instead...
hth
marcin
Windows Server > Directory Services
Comments
Post a Comment