Domain replication with firewall

Y

Yannick Robert

Hi,

I have tried to replicate same domain between 2 DC with SMTP replication,
but it was impossible. My problem is to replicate without any use of the
netbios & ldap ports.

there is a reason : i have a DC in the intranet, and another one in the DMZ.
Between them there is a firewall, and, of course, the netbios & ldap ports
are prohibited.

Is somebody know a solution to have the same accounts in the 2 DC.

Thanks in advance

Y.R.
 
Y

Yannick Robert

Thanks, it's a very good documentation about the different configurations
with a firewall
 
A

Ace Fekay [MVP]

In
Yannick Robert said:
Hi,

I have tried to replicate same domain between 2 DC with SMTP
replication, but it was impossible. My problem is to replicate
without any use of the netbios & ldap ports.

there is a reason : i have a DC in the intranet, and another one in
the DMZ. Between them there is a firewall, and, of course, the
netbios & ldap ports are prohibited.

Is somebody know a solution to have the same accounts in the 2 DC.

Thanks in advance

Y.R.

Sounds like a VPN between the two may be your better bet or a VPN to the
firewall allowing inside access. This way you only open the VPN ports.

NetBIOS ports wouldn't make a difference, but there are about 30 ports
needed for domain communication.

Active Directory Replication over Firewalls - Microsoft Service Providers:
http://www.microsoft.com/SERVICEPROVIDERS/columns/config_ipsec_p63623.asp

179442 - How to Configure a Firewall for Domains and Trusts:
http://support.microsoft.com/?id=179442

Q289241 - A List of the Windows 2000 Domain Controller Default Ports:
http://support.microsoft.com/default.aspx?scid=KB;EN-US;Q289241&

Restricting Active Directory Replication Traffic to a Specific Port
(Q224196):
http://support.microsoft.com/?id=224196
--
Regards,
Ace

Please direct all replies to the newsgroup so all can benefit.
This posting is provided "AS IS" with no warranties.

Ace Fekay, MCSE 2000, MCSE+I, MCSA, MCT, MVP
Microsoft Windows MVP - Active Directory
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top