Inter-Forest Firewall Ports


hi,

we setting separate forest in dmz; , have 1 in intranet - 2-way (selective auth) trust between them.

what ports need opened on firewall between dmz ad , intranet ad? far thinking of following:
- ldap (389)
- smb (445)
- kerberos (88)
- dns (53)

i did read on http://isc.sans.org/diary.html?storyid=7468 that once trust established, need keep kerberos (88) open on firewall.

could please confirm this, thank you.
tz

ultimately depends on goal. assume goes beyond establishing trust relationship. you should consult http://support.microsoft.com/kb/832017 to identify specific requirements corresponding functionality want make available...
considering circumstances, might want consider using ipsec instead...

hth
marcin


Windows Server  >  Directory Services



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client