Firewall GPO on Domain Controllers
hi,
i going through security audit. it kind of unexpected told particular lan wouldn't tested in audit. of course changed week before audit, tasked locking down domain quickly. one thing think i'm starting regret applying firewall gpo domain controllers. for won't go detail. i removed firewall configuration after suspecting replication issues. 2 of 3 dcs looked fine, 1 having problem has 2 of fsmo roles. before noticed issue, added win2k8 server core environment, did necessary stuff update schema etc. in past few days started getting "rpc endpoint mapper errors" on 1 server. again in interest in trying keep short:
when run netsh firewall
netsh firewall>show opmode domain profile configuration: ------------------------------------------------------------------- operational mode = enable exception mode = enable standard profile configuration (current): ------------------------------------------------------------------- operational mode = enable exception mode = enable local area connection firewall configuration: ------------------------------------------------------------------- operational mode = enable local area connection 2 firewall configuration: ------------------------------------------------------------------- operational mode = enable
clearly operational mode enable. have disabled firewall starting in services.msc, possible gpo still applied, because server can't data in domain? can make sure no firewall policy applied?
i have read document @ length: http://support.microsoft.com/default.aspx?scid=kb%3ben-us%3b839880
and haven't been able make progress. the document says use commands portqry -n <var style="-webkit-box-sizing: border-box;">problem_server</var> -o 1094,1025,1029,6004
to determine if ports being blocked, firewall service off, , yet ports either not listening/blocked or not viewable netstat.
how can confirm there not firewall policy on server?
thanks,
james
esmaeil,
that kind of thing worried about, wasn't issue, thankfully.
here url used solve issue.
http://support.microsoft.com/kb/224196/
for reason key set high number port 53,xxx think fine but, since didn't set , don't trust previous admin's knowledge of ad deleted rebooted , replication works again.
registry key 1
registry value: tcp/ip port
value type: reg_dword
value data: (available port)
Windows Server > Group Policy
Comments
Post a Comment