Quantcast
Channel: Directory Services forum
Viewing all articles
Browse latest Browse all 31638

Required ports for AD to replicate

$
0
0

hi there!

We have 2008 r2 domain controllers with domain and functional level 2008 r2.

We would like to install another DC in other location (locations are connected with site to site vpn).

I am familiar with this info: http://support.microsoft.com/kb/179442#method3, and http://social.technet.microsoft.com/wiki/contents/articles/584.active-directory-replication-over-firewalls.aspx but my question is in which direction must this ports be opened to/from other location? In both? From DC1 (in primary location) to DC2 (in secondary location), or from DC2 to DC1? Just one way or both directions? Who is the iniciator in the replication?

Does our network guys need to open this in both direction or in 1-way direction only?:

Client Port(s)Server PortService
49152 -65535/UDP123/UDPW32Time
49152 -65535/TCP135/TCPRPC Endpoint Mapper
49152 -65535/TCP464/TCP/UDPKerberos password change
49152 -65535/TCP49152-65535/TCPRPC for LSA, SAM, Netlogon (*)
49152 -65535/TCP/UDP389/TCP/UDPLDAP
49152 -65535/TCP636/TCPLDAP SSL
49152 -65535/TCP3268/TCPLDAP GC
49152 -65535/TCP3269/TCPLDAP GC SSL
53, 49152 -65535/TCP/UDP53/TCP/UDPDNS
49152 -65535/TCP49152 -65535/TCPFRS RPC (*)
49152 -65535/TCP/UDP88/TCP/UDPKerberos
49152 -65535/TCP/UDP445/TCPSMB
49152 -65535/TCP49152-65535/TCPDFSR RPC (*)

what does client ports stands for? In this case who's the client and who's the server?

with best regards,


bostjanc



Viewing all articles
Browse latest Browse all 31638

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>