<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Search results for 'app:weblogs' matching tags 'Active Directory Firewall Port' and 'Replication Ports Required'</title><link>http://msmvps.com/search/SearchResults.aspx?q=app:weblogs&amp;tag=Active+Directory+Firewall+Port,Replication+Ports+Required&amp;orTags=0&amp;o=DateDescending</link><description>Search results for 'app:weblogs' matching tags 'Active Directory Firewall Port' and 'Replication Ports Required'</description><dc:language>en-US</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Active Directory Lingering Objects, Journal Wraps, USN Rollbacks, Tombstone Lifetime, and Event IDs 13568, 13508, 1388, 1988, 2042, 2023, 2095, 1113, 1115, 2103, and more ...</title><link>http://msmvps.com/blogs/acefekay/archive/2011/12/27/active-directory-lingering-objects-journal-wraps-tombstone-lifetime-and-event-ids-13568-13508-1388-1988-2042-2023.aspx</link><pubDate>Tue, 27 Dec 2011 06:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1804134</guid><dc:creator>acefekay</dc:creator><description>&lt;h2&gt;Active Directory Lingering Objects, Journal Wraps, USN Rollbacks, Tombstone Lifetime, and Event IDs 13568, 13508, 1388, 1988, 2042, 2023, 2023, 2095, 1113, 1115, 2103, and more ...&lt;/h2&gt;
&lt;p&gt;Ace Fekay, MCT, MVP, MCITP EA, Exchange 2010 Enterprise Administrator, MCTS Windows 2008, Exchange 2010 &amp;amp; Exchange 2007, MCSE 2003/2000, MCSA Messaging 2003&lt;br /&gt;Microsoft Certified Trainer&lt;br /&gt;Microsoft MVP: Directory Services&lt;/p&gt;
&lt;p&gt;Posted 12/27/2011&lt;br /&gt;Updated 1/27/2012 - Clarified some of the Event ID 2042 repair steps&lt;br /&gt;Updated 3/27/2012 - Added info about and how to recover from USN Rollbacks&lt;/p&gt;
&lt;h3&gt;&lt;br /&gt;&lt;br /&gt;Journal Wrap - What does it mean?&lt;/h3&gt;
&lt;p&gt;To summarize, a Journal Wrap indicates it&amp;#39;s trying to replicate to another DC and the bad DC&amp;#39; FRS service may have been shut off for some reason. The Wrap error is based on the USN log or known as the USN Journal. Everything and anything that gets replicated has a USN, or Update Serial Number. Each DC has it&amp;#39;s own, and other DCs keep track of them so they know whether they have the other DCs&amp;#39; latest changes and are up to date on their own end. So generally, the USN Journal keeps track of changes made to any NTFR drive, whether for DFS, DC replication of SYSVOL, etc. If changes are made while the FRS service is shut down, it may get to a point where the last time something was changed, and when the FRS service is started, the last USN it&amp;#39;s aware of no longer exists (because that much time has passed by).&lt;/p&gt;
&lt;p&gt;DCs will also protect themselves against Lingering Objects in 2 ways:&lt;br /&gt;(1) By implementing strict replication&lt;br /&gt;(2) By isolating DCs that have NOT replicated with other DCs for more than the tombstone lifetime&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;To fix it, see &amp;quot;Fixing Journal Wraps&amp;quot; below in this blog.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Reference:&lt;/p&gt;
&lt;p&gt;Troubleshooting journal_wrap errors on Sysvol and DFS replica sets&lt;br /&gt;&lt;a href="http://support.microsoft.com/?id=292438"&gt;http://support.microsoft.com/?id=292438&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;br /&gt;Lingering objects &lt;/h3&gt;
&lt;p&gt;Lingering Objects occur if a domain controller will remain offline exceeding the Active Directory Tombstone Lifetime and thereby may retaining objects that have been permanently deleted from the directory on all other domain controllers in the domain and replication will be out of synch. The old data on the DC that hasn&amp;#39;t replicated are the Lingering Objects.&lt;/p&gt;
&lt;p&gt;If a DC is reintroduced past its tombstoned period (it&amp;#39;s point of no return), it can cause directory inconsistency and, under certain conditions, these objects can be reintroduced into the directory. Hence Lingering Objects.&lt;/p&gt;
&lt;p&gt;Also, to determine which DC has the lingering object, if there are&amp;nbsp;more than one DC, and all the DCs except one show a Lingering Object error, then the one that does not have an event ID showing a lingering object error, is the one with the lingering object that the other DCs are rejecting. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;To fix this, see the &amp;quot;Fixing Lingering Objects&amp;quot; section below in this blog.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Good thread regarding the AD Tombstone and Lingering Objects:&lt;br /&gt;Technet Forum: DC offline for 2 months, best way to handle?&lt;br /&gt;&lt;a href="http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/8c74df53-8042-423c-a801-7a7f38fdde7f"&gt;http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/8c74df53-8042-423c-a801-7a7f38fdde7f&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;br /&gt;Example Event ID 2042:&lt;/p&gt;
&lt;p&gt;Event Type:Error&lt;br /&gt;Event Source:NTDS Replication&lt;br /&gt;Event Category:Replication &lt;br /&gt;Event ID:2042&lt;br /&gt;Date:3/22/2005&lt;br /&gt;Time:7:28:49 AM&lt;br /&gt;User:NT AUTHORITY\ANONYMOUS LOGON&lt;br /&gt;Computer:DC3&lt;br /&gt;Description:&lt;br /&gt;It has been too long since this machine last replicated with the &lt;br /&gt;named source machine. The time between replications with this source &lt;br /&gt;has exceeded the tombstone lifetime. Replication has been stopped &lt;br /&gt;with this source. &lt;br /&gt;The reason that replication is not allowed to continue is that &lt;br /&gt;the two machine&amp;#39;s views of deleted objects may now be different. &lt;br /&gt;The source machine may still have copies of objects that have &lt;br /&gt;been deleted (and garbage collected) on this machine. If they &lt;br /&gt;were allowed to replicate, the source machine might return &lt;br /&gt;objects which have already been deleted. &lt;br /&gt;Time of last successful replication:&lt;br /&gt;2005-01-21 07:16:03 &lt;br /&gt;Invocation ID of source: &lt;br /&gt;0397f6c8-f6b8-0397-0100-000000000000 &lt;br /&gt;Name of source: &lt;br /&gt;4a8717eb-8e58-456c-995a-c92e4add7e8e._msdcs.contoso.com &lt;br /&gt;Tombstone lifetime (days):&lt;br /&gt;60&lt;/p&gt;
&lt;p&gt;The replication operation has failed.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;br /&gt;Other Event IDs associated with Lingering Objects and Journal Wraps:&lt;/h3&gt;
&lt;p&gt;2042&lt;br /&gt;2023&lt;br /&gt;1398&lt;br /&gt;1988&lt;br /&gt;1864&lt;br /&gt;13568&lt;br /&gt;NTFRS&lt;br /&gt;NTDS&lt;br /&gt;Or similar replication related errors.&lt;/p&gt;
&lt;p&gt;You maybe are able to get replication running again, see below about Event ID 2042. However, if you can&amp;#39;t get replication running again, you have to remove the outdated DC from the domain. If the original DC has other services installed, such as Exchange, this will complicate matters. (See section below about Exchange on a DC).&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;References:&lt;/p&gt;
&lt;p&gt;Event ID 1388 or 1988 A lingering object is detected Active Directory: &lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/Operations/77dbd146-f265-4d64-bdac-605ecbf1035f.mspx"&gt;http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/Operations/77dbd146-f265-4d64-bdac-605ecbf1035f.mspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Event ID 2042: It has been too long since this machine replicated:&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/Operations/34c15446-b47f-4d51-8e4a-c14527060f90.mspx"&gt;http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/Operations/34c15446-b47f-4d51-8e4a-c14527060f90.mspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Event ID 2042: It has been too long since this machine replicated&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc757610(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/cc757610(WS.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;The &amp;quot;Allow Replication With Divergent and Corrupt Partner&amp;quot; setting has to be set on all DCs.&lt;br /&gt;Fixing Replication Lingering Object Problems (Event IDs 1388, 1988, 2042)&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc949124(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/cc949124(WS.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Event ID 1388 or 1988: A lingering object is detected&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc780362(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/cc780362(WS.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;br /&gt;&lt;br /&gt;Why or how did this occur? &lt;/h3&gt;
&lt;p&gt;It could have been for a number of reasons:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Using the wrong DNS servers such as an external DNS, such as your ISP&amp;#39;s DNS server&lt;/li&gt;
&lt;li&gt;Using your router as a DNS address - Note: your router is not a DNS server&lt;/li&gt;
&lt;li&gt;Firewall blocks between the DCs, whether a perimeter firewall, firewall ruls on the VPN tunnels&lt;/li&gt;
&lt;li&gt;Antivirus software - many new antivirus sport a &amp;quot;network traffic protect&amp;quot; feature that act like a firewall that may block replication and other communication traffic.&lt;/li&gt;
&lt;li&gt;Security software blocking necessary traffic&lt;/li&gt;
&lt;li&gt;Windows Firewall not properly configured.&lt;/li&gt;
&lt;li&gt;Duplicate DNS zones&lt;/li&gt;
&lt;li&gt;MTU settings altered below 1500 on the VPN tunnel endpoints&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;First, you have to fix or address the above.&lt;/p&gt;
&lt;p&gt;Second, you have one of two choices:&lt;/p&gt;
&lt;p&gt;1. If you have one or two DCs, you&amp;#39;ll need to go through the process of edting the reg to force Journal Wrap restore, let it run, then turn it off. Both links supply the steps, with the second one right on the first page.&lt;br /&gt;2. If you have numerous DCs, or having difficult with this DC you may want to simply demote or force demote, seize FSMOs, run a metadata cleanup, and rebuild a new DC from scratch.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;To make sure your firewall ports are opened, what ports need to be opened, and information on using PortQry to check if the ports are opened, listening or allowed, see the following:&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;Active Directory Firewall Ports - Let&amp;#39;s Try To Make This Simple &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/acefekay/archive/2011/11/01/active-directory-firewall-ports-let-s-try-to-make-this-simple.aspx"&gt;http://msmvps.com/blogs/acefekay/archive/2011/11/01/active-directory-firewall-ports-let-s-try-to-make-this-simple.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;To check if you have any Duplicate AD Integrated DNS zones in the AD database:&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;Using ADSI Edit to Resolve Conflicting or Duplicate AD Integrated DNS zones &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/acefekay/archive/2009/09/02/using-adsi-edit-to-resolve-conflicting-or-duplicate-ad-integrated-dns-zones.aspx"&gt;http://msmvps.com/blogs/acefekay/archive/2009/09/02/using-adsi-edit-to-resolve-conflicting-or-duplicate-ad-integrated-dns-zones.aspx&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;&lt;br /&gt;Active Directory Tombstone Lifetime&lt;/h3&gt;
&lt;p&gt;The tombstone lifetime is listed in the schema.ini and will be set during the promotion of the first DC in the forest. The entry in the schema.ini &amp;quot;tombstoneLifetime=&amp;lt;number of days&amp;gt;&amp;quot;&lt;/p&gt;
&lt;p&gt;Therefore, the AD Tombstone Lifetime settings depends on the OS version used to initially created the first domain in your new forest years ago. The value will not change from the original installation. This setting will carry on from the original installation, even if you&amp;#39;ve migrated/updated all your DCs to the latest Windows versions and have updated the Forest and Domain Functional Levels. The AD Tombstone setting will not change from the original Forest implemenatation. It must be changed manually.&lt;/p&gt;
&lt;p&gt;Here&amp;#39;s the breakdown on what your Tombstone Lifetime settings may be:&lt;br /&gt;- Windows 2000 with all SPs = 60 Days&lt;br /&gt;- Windows Server 2003 without SP = 60 Days&lt;br /&gt;- Windows Server 2003 SP1 = 180 Days&lt;br /&gt;- Windows Server 2003 R2 SP1, installed with both R2 disks = 60 Days&lt;br /&gt;- Windows Server 2003 R2 SP1, installed with the 1st R2 disk = 180 Days&lt;br /&gt;- Windows Server 2003 SP2 = 180 Days&lt;br /&gt;- Windows Server 2003 R2 SP2 = 180 Days&lt;br /&gt;- Windows Server 2008 = 180 Days&lt;br /&gt;- Windows Server 2008 R2 = 180 Days&lt;/p&gt;
&lt;p&gt;&amp;nbsp;You can find what you&amp;#39;re current AD Tombstone setting is from one of the following methods. If the result of the query is set to &amp;lt;not set&amp;gt; , then it&amp;#39;s 60 days. Let&amp;#39;s change it to 180 days.&lt;/p&gt;
&lt;p&gt;Dsquery * &amp;quot;CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=Domain,DC=com&amp;quot; -attr tombstoneLifetime&lt;br /&gt;or&lt;br /&gt;dsquery * &amp;ldquo;cn=directory service,cn=windows nt,cn=services,cn=configuration,dc=corp,dc=domain,dc=com&amp;rdquo; &amp;ndash;scope base &amp;ndash;attr tombstonelifetime&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;Or you can use ADSI Edit to find and change it&lt;/p&gt;
&lt;p&gt;Double-click Configuration&lt;br /&gt;CN=Configuration&lt;br /&gt;ForestRootDomainName&lt;br /&gt;Services&lt;br /&gt;Windows NT&lt;br /&gt;Right-click CN=Directory Service, and then click Propertie&lt;br /&gt;In the Attribute column, click tombstoneLifetime.&lt;br /&gt;Note the value in the Value column. If the value is &amp;lt;not set&amp;gt;, the default value is 60 days.&lt;br /&gt;Change it to 180 days&lt;br /&gt;Close ADSI Edit&lt;br /&gt;Allow replication to occur.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;More info:&lt;/p&gt;
&lt;p&gt;Adjusting the Tombstone Lifetime, Ulf B. Simon-Weidner&amp;#39;s Blog:&lt;br /&gt;&amp;quot;However, if you want to raise the tombstone lifetime, e.g. from 60 to 180 to match the new default, there&amp;rsquo;s one scenario which needs to be considered:&lt;br /&gt;&amp;quot;Lets say we have two DCs, DC-Munich and DC-LA (L.A. because that where The Experts Conference will be in April). On DC-Munich we change the tombstoneLifetime from &amp;lt;not set&amp;gt; (=60) to 180. When garbage collection runs on DC-Munich it is bored &amp;ndash; it already cleaned up all changes from 60 days ago but we instructed it to keep everything now to 180 days, so the next 120 days garbage collection does not need to do anything.&amp;quot; &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/ulfbsimonweidner/archive/2010/02/10/adjusting-the-tombstone-lifetime.aspx"&gt;http://msmvps.com/blogs/ulfbsimonweidner/archive/2010/02/10/adjusting-the-tombstone-lifetime.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The default tombstone lifetime (TSL) value remains at 60 days instead of increasing to 180 days in Windows Server 2003 R2&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/924890"&gt;http://support.microsoft.com/kb/924890&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Excellent blog by Jorge that applies to Windows 2000/Windows 2003 SP1 and prior versions:&lt;/p&gt;
&lt;p&gt;If upgrading from Windows 2000 to 2003 SP1 or prior, the Schema will not get updated with the 180 day Tombstone. You will have to do it manually. It was fixed in SP2.&lt;br /&gt;Conclusion:&lt;br /&gt;&amp;nbsp;&amp;bull;If you install a W2K3 server from the first CD from the W2K3 R2 distribution set, then promote it to a DC and then install the R2 binaries from the second CD, the tombstone lifetime is set to 180 days &lt;br /&gt;&amp;nbsp;&amp;bull;If you install a W2K3 server from the first CD from the W2K3 R2 distribution set, then install the R2 binaries from the second CD and then promote it to a DC, the tombstone lifetime is set to &amp;lt;not set&amp;gt; which is 60 days!&lt;br /&gt;or simply put... a BUG after installing the R2 binaries, but before promoting the first DC to create the AD forest.&lt;br /&gt;The solution: manually (or through a script or a command line tool) change the value yourself to 180 for the attribute mentioned earlier.&lt;br /&gt;&lt;a href="http://blogs.dirteam.com/blogs/jorge/archive/2006/07/23/1233.aspx"&gt;http://blogs.dirteam.com/blogs/jorge/archive/2006/07/23/1233.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;br /&gt;&lt;br /&gt;Event IDs possibily associated with Journal Wraps: &lt;/h3&gt;
&lt;p&gt;Most common one is:&lt;br /&gt;EventID 13568&lt;/p&gt;
&lt;p&gt;Event Type: Error&lt;br /&gt;Event Source: NtFrs&lt;br /&gt;Event Category: None&lt;br /&gt;Event ID: 13568&lt;br /&gt;Date: Whenever&lt;br /&gt;Time: Whenever&lt;br /&gt;User: N/A&lt;br /&gt;Computer: computername&lt;br /&gt;Description:&lt;br /&gt;The File Replication Service has detected that the replica set &amp;quot;DOMAIN&lt;br /&gt;SYSTEM VOLUME (SYSVOL SHARE)&amp;quot; is in JRNL_WRAP_ERROR.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;An Event ID 13568 usually means there is a corruption with the FRS data in the shared folder that used by NTFRS between DC for replication, or the DC has been disconnected longer than the tombstone lifetime (tombstone time varies based on operating systems), or something else occured, such as a hiccup with a NIC driver, power surge, etc.&lt;/p&gt;
&lt;p&gt;Bascially, it&amp;#39;s saying you&amp;#39;ll need to go through the process of edting the reg to force Journal Wrap restore, let it run, then turn it off. Both links supply the steps, with the second one right on the first page.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;To fix it, see the &amp;quot;Fixing a Journal Wrap&amp;quot; section below in this blog.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;References:&lt;/p&gt;
&lt;p&gt;EventID 13568&lt;br /&gt;&lt;a href="http://eventid.net/display.asp?eventid=13568&amp;amp;eventno=1743&amp;amp;source=NtFrs&amp;amp;phase=1"&gt;http://eventid.net/display.asp?eventid=13568&amp;amp;eventno=1743&amp;amp;source=NtFrs&amp;amp;phase=1&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;EventID 13568 and Journal Wrap Error&lt;br /&gt;&lt;a href="http://www.petri.co.il/forums/showthread.php?t=7122"&gt;http://www.petri.co.il/forums/showthread.php?t=7122&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;a href="http://eventid.net/display.asp?eventid=13568&amp;amp;eventno=1743&amp;amp;source=NtFrs&amp;amp;phase=1"&gt;http://eventid.net/display.asp?eventid=13568&amp;amp;eventno=1743&amp;amp;source=NtFrs&amp;amp;phase=1&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thread: &amp;quot;Jrnl_wrap_error&amp;quot;&lt;br /&gt;&lt;a href="http://www.petri.co.il/forums/showthread.php?t=7122"&gt;http://www.petri.co.il/forums/showthread.php?t=7122&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;/h3&gt;
&lt;h3&gt;&lt;br /&gt;Event ID 13508: &lt;/h3&gt;
&lt;p&gt;Example:&lt;/p&gt;
&lt;p&gt;Source FRS &lt;br /&gt;Type Error &lt;br /&gt;Description The File Replication Service is having trouble enabling replication from &amp;lt;server&amp;gt; to &amp;lt;server&amp;gt; for &amp;lt;path&amp;gt; using the DNS name &amp;lt;name&amp;gt;. FRS will keep retrying.&lt;br /&gt;Following are some of the reasons you would see this warning.&lt;/p&gt;
&lt;p&gt;[1] FRS can not correctly resolve the DNS name &amp;lt;name&amp;gt; from this computer.&lt;br /&gt;[2] FRS is not running on &amp;lt;name&amp;gt;.&lt;br /&gt;[3] The topology information in the Active Directory for this replica has not yet replicated to all the Domain Controllers.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This is indicative of FRS replication problems. Check FRS event logs on both computers. If Event ID 13508 is present, there may be a problem with the RPC service on either computer&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/272279"&gt;http://support.microsoft.com/kb/272279&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;To fix it, you&amp;#39;ll need to set the Burflag options to kick it off again (see &amp;quot;Fixing a Journal Wrap&amp;quot; below), that is as long as all ports between all locations and have been confirmed wide opened, and no local antivirus or security software is blocking necessary network traffic to and from the machine, and as long as this is under 180 days. Any longer, the DC would have to be forced demoted.&lt;/p&gt;
&lt;p&gt;The high level steps are basically to first make sure that the FRS service is running. Then to kick off replication and rebuild the Sysvol, you&amp;#39;ll want to set the Burflag value on the good DC to D4, then set the Burflag value to D2 on ALL other DCs in that domain. Please read the detailed steps in the following link. Scroll down to the section titled, &amp;quot;How to rebuild the domain SYSVOL replica set across enterprise environments&amp;quot; in the following link:&lt;/p&gt;
&lt;p&gt;How to rebuild the SYSVOL tree and its content in a domain. &lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/315457"&gt;http://support.microsoft.com/kb/315457&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;More info here:&lt;br /&gt;Using the BurFlags registry key to reinitialize File Replication&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/290762"&gt;http://support.microsoft.com/kb/290762&lt;/a&gt;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;Troubleshooting journal_wrap errors on Sysvol and DFS replica sets ibn Windows 2000 (EOL)&lt;br /&gt;&lt;a href="http://support.microsoft.com/?id=292438"&gt;http://support.microsoft.com/?id=292438&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;br /&gt;&lt;br /&gt;Is Exchange or any other high demand service installed on the DC?&lt;/h3&gt;
&lt;p&gt;&lt;br /&gt;Exchange, SQL, CRM, Sharepoint, etc, will highly complicate matters to recover the machine. It&amp;#39;s highly suggested to not intall anything on a DC other than DNS, DHCP or WINS. Installing any other service or high level app will complicate or vastly affect DC operations, especially making recoverability highly complex, especially if you are at the point that the DC is not recoverable. This will vastly impact Exchange, because Exchange will &amp;quot;lock&amp;quot; on to the GC service on the DC it is installed on and will not look elsewhere for a GC, even if you have a numerous GCs.&lt;/p&gt;
&lt;p&gt;Read more on Exchange or any other app on a DC and it&amp;#39;s impact on the DC and the impact on Exchange or whatever is installed on the DC:&lt;/p&gt;
&lt;p&gt;Exchange on a Domain Controller - Ramifications and How to Move Exchange off a DC&lt;br /&gt;&lt;a href="http://msmvps.com/blogs/acefekay/archive/2009/08/08/moving-from-exchange-2000-currently-on-a-windows-2000-domain-controller-to-a-new-exchange-2003-server-on-a-windows-2003-member-server.aspx"&gt;http://msmvps.com/blogs/acefekay/archive/2009/08/08/moving-from-exchange-2000-currently-on-a-windows-2000-domain-controller-to-a-new-exchange-2003-server-on-a-windows-2003-member-server.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;&lt;br /&gt;&lt;br /&gt;Fixing a Journal Wrap &lt;/h2&gt;
&lt;p&gt;The following will help to kick off replication and rebuild SYSVOL to get it out of a Journal Wrap state.&lt;/p&gt;
&lt;h4&gt;Assocated Event ID: 13568, 13508&lt;/h4&gt;
&lt;p&gt;Note:&lt;br /&gt;If it&amp;#39;s the only DC in the network then set Burflags to D4 (also known as an authoritative mode restore) to rebuild it from scratch. &lt;br /&gt;If there are more than one DC, you will want to set Burflags do D2 (also known as a nonauthoritative mode restore) to pull a copy from an existing DC.&lt;/p&gt;
&lt;p&gt;Keep in mind, the use of the Burflags key to fix Journal Wrap Errors instead of &amp;quot;Enable Journal Wrap Automatic Restore&amp;quot; also prevents you from seeing a an empty SYSVOL. &lt;/p&gt;
&lt;p&gt;Using &amp;quot;Enable Journal Wrap Automatic Restore&amp;quot; will make NTFRS reinitialize all NTFRS shares and delete all contents in those shares. However, this is a very aggressive and destructive approach and you may lose data, such as any logon scripts, etc.&lt;/p&gt;
&lt;p&gt;Instead, just use the &amp;quot;Burflags&amp;quot; key and set it to &amp;quot;D4&amp;quot; and restart NTFRS. You will see it fix itself and SYSVOL and NETLOGON will still have its contents after the restore.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4&gt;To perform a nonauthoritative restore, stop the FRS service (using the D2 option), configure the BurFlags registry key, and then restart the FRS service. To do so: &lt;/h4&gt;
&lt;p&gt;1.Click Start, and then click Run.&lt;br /&gt;2.In the Open box, type cmd and then press ENTER.&lt;br /&gt;3.In the Command box, type net stop ntfrs.&lt;br /&gt;4.Click Start, and then click Run.&lt;br /&gt;5.In the Open box, type regedit and then press ENTER.&lt;br /&gt;6.Locate the following subkey in the registry: &lt;/p&gt;
&lt;p&gt;HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NtFrs\Parameters\Backup/Restore\Process at Startup&lt;/p&gt;
&lt;p&gt;7.In the right pane, double-click BurFlags.&lt;br /&gt;8.In the Edit DWORD Value dialog box, type D2 and then click OK.&lt;br /&gt;9.Quit Registry Editor, and then switch to the Command box.&lt;br /&gt;10.In the Command box, type net start ntfrs.&lt;br /&gt;11.Quit the Command box.&lt;/p&gt;
&lt;p&gt;When the FRS service restarts, the following actions occur: &lt;/p&gt;
&lt;p&gt;&amp;bull; The value for BurFlags registry key returns to 0. &lt;br /&gt;&amp;bull; Files in the reinitialized FRS folders are moved to a Pre-existing folder.&lt;br /&gt;&amp;bull; An event 13565 is logged to signal that a nonauthoritative restore is started. &lt;br /&gt;&amp;bull; The FRS database is rebuilt.&lt;br /&gt;&amp;bull; The member performs an initial join of the replica set from an upstream partner or from the computer that is specified in the Replica Set Parent registry key if a parent has been specified for SYSVOL replica sets.&lt;br /&gt;&amp;bull; The reinitialized computer runs a full replication of the affected replica sets when the relevant replication schedule begins.&lt;br /&gt;&amp;bull; When the process is complete, an event 13516 is logged to signal that FRS is operational. If the event is not logged, there is a problem with the FRS configuration. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4&gt;&lt;br /&gt;To complete an authoritative restore (using the D4 option), stop the FRS service, configure the BurFlag registry key, and then restart the FRS service. To do so: &lt;/h4&gt;
&lt;p&gt;1.Click Start, and then click Run.&lt;br /&gt;2.In the Open box, type cmd and then press ENTER.&lt;br /&gt;3.In the Command box, type net stop ntfrs.&lt;br /&gt;4.Click Start, and then click Run.&lt;br /&gt;5.In the Open box, type regedit and then press ENTER.&lt;br /&gt;6.Locate the following subkey in the registry: &lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NtFrs\Parameters\Backup/Restore\Process at Startup&lt;/p&gt;
&lt;p&gt;7.In the right pane, double click BurFlags.&lt;br /&gt;8.In the Edit DWORD Value dialog box, type D4 and then click OK.&lt;br /&gt;9.Quit Registry Editor, and then switch to the Command box.&lt;br /&gt;10.In the Command box, type net start ntfrs.&lt;br /&gt;11.Quit the Command box.&lt;/p&gt;
&lt;p&gt;When the FRS service is restarted, the following actions occur: &lt;/p&gt;
&lt;p&gt;&amp;bull; The value for the BurFlags registry key is set back to 0. &lt;br /&gt;&amp;bull; An event 13566 is logged to signal that an authoritative restore is started.&lt;br /&gt;&amp;bull; Files in the reinitialized FRS replicated directories remain unchanged and become authoritative on direct replication. Additionally, the files become indirect replication partners through transitive replication.&lt;br /&gt;&amp;bull; The FRS database is rebuilt based on current file inventory.&lt;br /&gt;&amp;bull; When the process is complete, an event 13516 is logged to signal that FRS is operational. If the event is not logged, there is a problem with the FRS configuration. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;References:&lt;/p&gt;
&lt;p&gt;More specifics, see:&lt;br /&gt;Using the BurFlags registry key to reinitialize File Replication Service replica sets: &lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/290762"&gt;http://support.microsoft.com/kb/290762&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;How to rebuild the SYSVOL tree and its content in a domain. &lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/315457"&gt;http://support.microsoft.com/kb/315457&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Kicking NTFRS to start replicating after SYSVOL non-auth. restore &lt;br /&gt;&lt;a href="http://blogs.dirteam.com/blogs/jorge/archive/2006/05/12/Kicking-NTFRS-to-start-replicating-after-SYSVOL-non_2D00_auth.-restore.aspx"&gt;http://blogs.dirteam.com/blogs/jorge/archive/2006/05/12/Kicking-NTFRS-to-start-replicating-after-SYSVOL-non_2D00_auth.-restore.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;&lt;br /&gt;&lt;br /&gt;Fixing Lingering Objects:&lt;/h2&gt;
&lt;h4 style="padding-left:30px;"&gt;Associated Event ID: 2042:&lt;/h4&gt;
&lt;p style="padding-left:30px;"&gt;It has been too long since this machine replicated&lt;br /&gt;Lingering Objects&lt;br /&gt;EventID 2042&lt;br /&gt;EventID 1388&lt;br /&gt;EventID 1988&lt;br /&gt;EventID 13508&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;&lt;br /&gt;To reinitialize replication due to lingering objects, which is due to replication failing far beyond the Tombstone AD limit.&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;Below is from: &lt;br /&gt;Event ID 2042: It has been too long since this machine replicated&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc757610(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/cc757610(WS.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;========================================================================&lt;br /&gt;&lt;strong&gt;An example of an Event ID 2042:&lt;/strong&gt;&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;Event Type:Error&lt;br /&gt;Event Source:NTDS Replication&lt;br /&gt;Event Category:Replication &lt;br /&gt;Event ID:2042&lt;br /&gt;Date:3/22/2005&lt;br /&gt;Time:7:28:49 AM&lt;br /&gt;User:NT AUTHORITY\ANONYMOUS LOGON&lt;br /&gt;Computer:DC3&lt;br /&gt;Description:&lt;br /&gt;It has been too long since this machine last replicated with the &lt;br /&gt;named source machine. The time between replications with this source &lt;br /&gt;has exceeded the tombstone lifetime. Replication has been stopped &lt;br /&gt;with this source. &lt;br /&gt;The reason that replication is not allowed to continue is that &lt;br /&gt;the two machine&amp;#39;s views of deleted objects may now be different. &lt;br /&gt;The source machine may still have copies of objects that have &lt;br /&gt;been deleted (and garbage collected) on this machine. If they &lt;br /&gt;were allowed to replicate, the source machine might return &lt;br /&gt;objects which have already been deleted. &lt;br /&gt;Time of last successful replication:&lt;br /&gt;2005-01-21 07:16:03 &lt;br /&gt;Invocation ID of source: &lt;br /&gt;0397f6c8-f6b8-0397-0100-000000000000 &lt;br /&gt;Name of source: &lt;br /&gt;4a8717eb-8e58-456c-995a-c92e4add7e8e._msdcs.contoso.com &lt;br /&gt;Tombstone lifetime (days):&lt;br /&gt;60&lt;br /&gt;The replication operation has failed.&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;User Action:&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;Determine which of the two machines was disconnected from the &lt;br /&gt;forest and is now out of date. You have three options: &lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;1. Demote or reinstall the machine(s) that were disconnected. &lt;br /&gt;2. Use the &amp;quot;repadmin /removelingeringobjects&amp;quot; tool to remove &lt;br /&gt;inconsistent deleted objects and then resume replication. &lt;br /&gt;3. Resume replication. Inconsistent deleted objects may be introduced. &lt;br /&gt;You can continue replication by using the following registry key. &lt;br /&gt;Once the systems replicate once, it is recommended that you remove &lt;br /&gt;the key to reinstate the protection. &lt;br /&gt;Registry Key: &lt;br /&gt;HKLM\System\CurrentControlSet\Services\NTDS\Parameters\Allow Replication With Divergent and Corrupt Partner&lt;br /&gt;========================================================================&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;To check which DC has not replicated longer than the tombstone lifetime:&lt;/h3&gt;
&lt;p style="padding-left:30px;"&gt;Check each DC for an Event ID 2042, &lt;br /&gt;Then run repadmin /showrepl on this specific DC that shows this error.&lt;br /&gt;The repadmin /showrepl command may also report error 8614 on the DC in question:&lt;br /&gt;=============================================================&lt;br /&gt;Source: Default-First-Site-Name\DC1&lt;br /&gt;******* 1502 CONSECUTIVE FAILURES since 2005-01-21 07:16:00&lt;br /&gt;Last error: 8614 (0x21a6):&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The Active Directory cannot replicate with this server &lt;br /&gt;because the time since the last replication with this server has &lt;br /&gt;exceeded the tombstone lifetime.&lt;br /&gt;============================================================= &lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;Then fun the following procedure to reinitialized replication:&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;From:&lt;br /&gt;Event ID 1388 or 1988: A lingering object is detected.&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc780362(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/cc780362(WS.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;Then restart replication:&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;Restart Replication Following an Event ID 2042&lt;br /&gt;To restart inbound replication on the destination domain controller following event ID 2042, you must edit the Allow Replication With Divergent and Corrupt Partner registry entry in &lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters.&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&amp;nbsp;Steps to kick off replication after an Event ID 2042:&lt;/h3&gt;
&lt;p&gt;1. Expand &amp;quot;HKLM\System\CurrentControlSet\Services\NtFrs\Parameters&amp;quot;&lt;/p&gt;
&lt;p&gt;If the registry entry exists in the details pane, modify the entry as follows:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;In the details pane, right-click &lt;strong&gt;Allow Replication With Divergent and Corrupt Partner&lt;/strong&gt;, and then click Modify.&lt;/li&gt;
&lt;li&gt;In the Value data box, type 1, and then click OK.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If the registry entry does not exist, create the entry as follows:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Right-click Parameters, click New, and then click DWORD Value.&lt;/li&gt;
&lt;li&gt;Type the name &lt;strong&gt;Allow Replication With Divergent and Corrupt Partner&lt;/strong&gt;, and then press ENTER.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;2. Change value for &amp;quot;&lt;strong&gt;Enable Journal Wrap Automatic Restore&lt;/strong&gt;&amp;quot; from 0 to 1.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;If the DWORD Value does not exist, create a new one with the exact spelling as above, including spaces but without the quotes.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;3. Stop the NTFRS Service (open a command prompt and type &amp;quot;net stop ntfrs&amp;quot;)&lt;/p&gt;
&lt;p&gt;4. Start the NTFRS Service (net start ntfrs)&lt;/p&gt;
&lt;p&gt;5. Monitor the File Replication Service Event Logs for events:&lt;br /&gt;&amp;bull; 13553 &amp;ndash; The DC is performing the recovery process&lt;br /&gt;&amp;bull; 13554 &amp;ndash; The DC is ready to pull the replica from another DC.&lt;br /&gt;&amp;bull; 13516 - At this point go to step 6. (the problem is resolved if you receive this event)&lt;/p&gt;
&lt;p&gt;6. Using a command prompt type: &amp;quot;net share&amp;quot; and look for the Netlogon and Sysvol Shares to appear. The Journal Wrap error is only fixed after the Domain Controller receives the new SYSVOL replica from a peer Domain Controller. This may take a period of time depending on where your peer DC is located and on bandwidth.&lt;/p&gt;
&lt;p&gt;7. Reset the Registry to Protect Against Outdated Replication&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;When you are satisfied that lingering objects have been removed and replication has occurred successfully from the source domain controller, edit the registry to return the following values to Zero (0):&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Change the value for &amp;quot;&lt;strong&gt;Allow Replication With Divergent and Corrupt Partner&lt;/strong&gt;&amp;quot; to 0.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;br /&gt;Reference:&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;Event ID 2042: It has been too long since this machine replicated&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc757610(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/cc757610(WS.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;Event ID 13568:&lt;br /&gt;&lt;a href="http://www.eventid.net/display.asp?eventid=13568&amp;amp;source"&gt;http://www.eventid.net/display.asp?eventid=13568&amp;amp;source&lt;/a&gt;= &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;&lt;br /&gt;If you can&amp;#39;t get replication to reinitialize&lt;/h3&gt;
&lt;p&gt;Now if it continues after these steps, then you would need to run an Authoritative Restore. Do you have a backup? If not, and nothing else is running on it, and you have other DCs, I would force demote it, then re-promote it back into a DC. Or simply transfer FSMOs, demote it and rebuild it from scratch. &lt;/p&gt;
&lt;p&gt;If you have many DCs and this is not possible or feasible:&lt;/p&gt;
&lt;p&gt;Simply transfer FSMOs, demote it and rebuilt it from scratch. If you can&amp;#39;t transfer the FSMOs and/or you can&amp;#39;t demote it properly, force demote it using dcpromo /forceremoval, seize any FSMOs, run a metadata cleanup, and rebuilt it from scratch. See the following for more info:&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;Remove a Current Operational Domain Controller from Active Directory (Includes tranferring FSMO roles, DNS settings, Time settings, WINS settings, etc)&lt;br /&gt;&lt;a href="http://msmvps.com/blogs/acefekay/archive/2010/10/09/remove-a-current-operational-domain-controller-from-active-directory.aspx"&gt;http://msmvps.com/blogs/acefekay/archive/2010/10/09/remove-a-current-operational-domain-controller-from-active-directory.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;Complete Step by Step Guideline to Remove an Orphaned Domain controller &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/acefekay/archive/2010/10/05/complete-step-by-step-to-remove-an-orphaned-domain-controller.aspx"&gt;http://msmvps.com/blogs/acefekay/archive/2010/10/05/complete-step-by-step-to-remove-an-orphaned-domain-controller.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;.&lt;/p&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;h2&gt;USN Rollbacks&lt;/h2&gt;
&lt;p&gt;USN Rollbacks occur from using a virtualized&amp;nbsp;snapshot (HyperV or VMWare) to recover a DC. Snapshots are not supported, for obvious reasons. &lt;/p&gt;
&lt;p&gt;The following is quoted from&lt;em&gt; &lt;/em&gt;&lt;a href="http://support.microsoft.com/kb/875495%20" title="How to detect and recover from a USN Rollbak in Windwos 2003, 2008 or 2008 R2"&gt;&lt;em&gt;KB875495&lt;/em&gt;&lt;/a&gt;&lt;em&gt;:&lt;/em&gt;&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;Bascially, a USN Rollback is a&lt;em&gt;&amp;nbsp;&amp;nbsp;&amp;quot; [...] condition that occurs when a domain controller that is running Windows 2000, Windows Server 2003, Windows Server 2008, or Windows Server 2008 R2 starts from an Active Directory database that has been incorrectly restored or copied into place. This condition is known as an update sequence number rollback, or&lt;/em&gt; &lt;em&gt;USN rollback.&lt;br /&gt;&lt;br /&gt;When a USN rollback occurs, modifications to objects and attributes that occur on one domain controller do not replicate to other domain controllers in the forest. Because replication partners believe that they have an up-to-date copy of the Active Directory database, monitoring and troubleshooting tools such as Repadmin.exe do not report any replication errors.&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;h3&gt;Associated Event IDs with USN Rollbacks:&lt;/h3&gt;
&lt;p style="padding-left:30px;"&gt;&lt;em&gt;Event Source: NTDS Replication &lt;br /&gt;Event Category: Replication &lt;br /&gt;Event ID: 2095 &lt;/em&gt;&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;&lt;em&gt;Event Source: NTDS General &lt;br /&gt;Event Category: Replication &lt;br /&gt;Event ID: 1113 &lt;/em&gt;&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;&lt;em&gt;Event Source: NTDS General &lt;br /&gt;Event Category: Replication &lt;br /&gt;Event ID: 1115 &lt;/em&gt;&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;&lt;em&gt;Event Source: NTDS General &lt;br /&gt;Event Category: Service Control &lt;br /&gt;Event ID: 2103&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;h3&gt;How to fix a USN Rollback?&lt;/h3&gt;
&lt;p&gt;&lt;em&gt;In summary, &lt;/em&gt;&lt;strong&gt;&lt;span style="text-decoration:underline;"&gt;The easiest way out of a USN Rollback&lt;/span&gt;&lt;/strong&gt; is to simply unplug the machine, run a metadata cleanup, then re-build it from scratch (&lt;strong&gt;do NOT use a cloned image&lt;/strong&gt;), then promote it back into the domain., You may want to take a look at this:&lt;/p&gt;
&lt;p style="padding-left:60px;"&gt;How to detect and recover from a USN rollback in Windows Server 2003, Windows Server 2008, and Windows Server 2008 R2&lt;br /&gt;Feb 10, 2011 &amp;ndash; Explains how to recover when a domain controller is incorrectly rolled back by using an image-based installation of the operating system.&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/875495"&gt;http://support.microsoft.com/kb/875495&lt;/a&gt;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;If you opt to &amp;quot;unplug&amp;quot; the DC, as mentioned in the above KB article, then you can follow this step by step:&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;Complete Step by Step Guideline to Remove an Orphaned Domain controller (including seizing FSMOs, running a metadata cleanup, cleanup DNS, Sites, and more)&lt;br /&gt;&lt;a href="http://msmvps.com/blogs/acefekay/archive/2010/10/05/complete-step-by-step-to-remove-an-orphaned-domain-controller.aspx"&gt;http://msmvps.com/blogs/acefekay/archive/2010/10/05/complete-step-by-step-to-remove-an-orphaned-domain-controller.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;h3&gt;In addition, there is another option to fix a USN Rollback:&lt;/h3&gt;
&lt;p&gt;If you don&amp;#39;t want to unplug it, metadata cleanup, etc. It&amp;#39;s a method by Paul Bergson. It uses an unsupported method by Microsoft, but it works. You have to dig in and alter the Invocation ID using repadmin, the registry, etc. Tedious, but it works.&lt;/p&gt;
&lt;p style="padding-left:30px;"&gt;Restoring a Virtual DC from a Snapshot, by Paul Bergson&lt;br /&gt;&lt;a href="http://blogs.dirteam.com/blogs/paulbergson/archive/2011/01/14/restoring-a-dc-from-a-snapshot.aspx"&gt;http://blogs.dirteam.com/blogs/paulbergson/archive/2011/01/14/restoring-a-dc-from-a-snapshot.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;h2&gt;&lt;br /&gt;General References:&lt;/h2&gt;
&lt;p&gt;&lt;br /&gt;Fixing Replication Lingering Object Problems (Event IDs 1388, 1988, 2042)&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc738018(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/cc738018(WS.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Event ID 2042: It has been too long since this machine replicated &lt;br /&gt;This shows you how to recover a DC that has not replicated beyond the Tombstone LIfetime&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc757610(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/cc757610(WS.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Determining the forest Active Directory (and ADAM/ADLDS) Tombstone Lifetime using Joe Richard&amp;#39;s ADFind&lt;br /&gt;&lt;a href="http://blog.joeware.net/2010/02/05/1896/"&gt;http://blog.joeware.net/2010/02/05/1896/&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Determine the tombstone lifetime for the forest&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc784932(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/cc784932(WS.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Reconnecting a Domain Controller After a Long-Term Disconnection&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc786630(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/cc786630(WS.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;What happens when the disconnection of a DC exceeds the Tombstone Lifetime?&lt;br /&gt;&lt;a href="http://blogs.dirteam.com/blogs/jorge/archive/2005/11/24/153.aspx"&gt;http://blogs.dirteam.com/blogs/jorge/archive/2005/11/24/153.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Lingering objects &lt;br /&gt;&lt;a href="http://blogs.dirteam.com/blogs/jorge/archive/2006/05/08/Lingering-objects.aspx"&gt;http://blogs.dirteam.com/blogs/jorge/archive/2006/05/08/Lingering-objects.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Help, I&amp;#39;ve lost my SYSVOL and can&amp;#39;t get it up&lt;br /&gt;&lt;a href="http://msmvps.com/blogs/bradley/archive/2007/12/27/help-i-ve-lost-my-sysvol-and-can-t-get-up.aspx"&gt;http://msmvps.com/blogs/bradley/archive/2007/12/27/help-i-ve-lost-my-sysvol-and-can-t-get-up.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;======&lt;br /&gt;Related Additional Links&lt;/p&gt;
&lt;p&gt;Active Directory Inside Out (5 of 10): DNS Features and Configuration (First Question):&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/community/chats/trans/windowsnet/wnet_111204.mspx"&gt;http://www.microsoft.com/technet/community/chats/trans/windowsnet/wnet_111204.mspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Things to consider when a Windows Server 2003-based domain controller or a Windows 2000-based domain controller runs in a virtual environment (VPC, HyperV or VMWare): &lt;br /&gt;&lt;a href="http://support.microsoft.com/?id=888794"&gt;http://support.microsoft.com/?id=888794&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;What happens when the disconnection of a DC exceeds the Tombstone Lifetime? &lt;br /&gt;&lt;a href="http://blogs.dirteam.com/blogs/jorge/archive/2005/11/24/153.aspx"&gt;http://blogs.dirteam.com/blogs/jorge/archive/2005/11/24/153.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Lingering objects &lt;br /&gt;&lt;a href="http://blogs.dirteam.com/blogs/jorge/archive/2006/05/08/Lingering-objects.aspx"&gt;http://blogs.dirteam.com/blogs/jorge/archive/2006/05/08/Lingering-objects.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Troubleshooting Active Directory Replication Problems&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc738415.aspx"&gt;http://technet.microsoft.com/en-us/library/cc738415.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Outdated Active Directory objects generate event ID 1988 in Windows Server 2003&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/870695"&gt;http://support.microsoft.com/kb/870695&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Event ID 1388 or 1988: A lingering object is detected&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc780362(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/cc780362(WS.10).aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Lingering objects may remain after you bring an out-of-date global catalog server back online&lt;br /&gt;&lt;a href="http://support.microsoft.com/default.aspx/kb/314282"&gt;http://support.microsoft.com/default.aspx/kb/314282&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;br /&gt;Fixing Replication DNS Lookup Problems (Event IDs 1925, 2087, 2088)&lt;br /&gt;&lt;a href="http://technet2.microsoft.com/WindowsServer/en/Library/43e6f617-fb49-4bb4-8561-53310219f9971033.mspx"&gt;http://technet2.microsoft.com/WindowsServer/en/Library/43e6f617-fb49-4bb4-8561-53310219f9971033.mspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Fixing Replication Connectivity Problems (Event ID 1925)&lt;br /&gt;&lt;a href="http://technet2.microsoft.com/WindowsServer/en/Library/7fcaa311-bc19-479d-9a4e-179704dfe08f1033.mspx?mfr=true"&gt;http://technet2.microsoft.com/WindowsServer/en/Library/7fcaa311-bc19-479d-9a4e-179704dfe08f1033.mspx?mfr=true&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Fixing Replication Topology Problems (Event ID 1311) ?&lt;br /&gt;&lt;a href="http://technet2.microsoft.com/WindowsServer/en/Library/062e8eaa-27e0-4c5e-bc2b-2913ecce24b81033.mspx"&gt;http://technet2.microsoft.com/WindowsServer/en/Library/062e8eaa-27e0-4c5e-bc2b-2913ecce24b81033.mspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;Ace Fekay&lt;/h2&gt;
&lt;p&gt;Corrections, comments and suggestions are welcomed.&lt;/p&gt;</description></item><item><title>Active Directory Firewall Ports - Let's Try To Make This Simple</title><link>http://msmvps.com/blogs/acefekay/archive/2011/11/01/active-directory-firewall-ports-let-s-try-to-make-this-simple.aspx</link><pubDate>Tue, 01 Nov 2011 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1801962</guid><dc:creator>acefekay</dc:creator><description>&lt;p&gt;Ace Fekay, MCT, MVP, MCITP EA, MCTS Windows 2008, Exchange 2007 &amp;amp; Exchange 2010, Exchange 2010 Enterprise Administrator, MCSE 2003/2000, MCSA Messaging 2003&lt;br /&gt;Microsoft Certified Trainer&lt;br /&gt;Microsoft MVP: Directory Services&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;Original Publication Date: 11/1/2011&lt;br /&gt;Port Matrix Table Resized to fit in browser - 12/7/2011&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;&lt;/h2&gt;
&lt;h2&gt;RPC server not available?&lt;br /&gt;Replication errors in the Event viewer?&lt;/h2&gt;
&lt;h4&gt;Sound familiar?&lt;/h4&gt;
&lt;p&gt;If so, you&amp;#39;ve been succumbed to the fact and realization there are possibly necessary ports being blocked causing these errors. Whether between locations with firewall/VPN tunnel port blocks, Windows Firewall (which is usually not the culprit), or even security software or antivirus apps with some sort of &amp;quot;network traffic protection&amp;quot; feature enabled that is causing the problems. &lt;/p&gt;
&lt;p&gt;Simply speaking, if there are replication or other AD communication problems, and you have an antivirus software installed on the endpoints or installed on all of&amp;nbsp; your DCs, disable it, or better yet, uninstall it. Uninstalling it is the best bet, so you know tehre are no traces of other subcomponents that are active that may still be causing the block. If after uninstalling it, and you find replication now works, well there you have it. At that point, you&amp;#39;ll need to contact your antivirus vendor to ask them the best way to configure it to allow AD communications and replication.&lt;/p&gt;
&lt;p&gt;If it&amp;#39;s not your antivirus or security app, and disabling the Windows firewall doesn&amp;#39;t do the trick, then it&amp;#39;s obvious it&amp;#39;s an outside factor - your firewalls.&lt;/p&gt;
&lt;p&gt;Also to point out, when testing for port blocks, tools such as telnet is not a good tool to test AD/DC to DC connectivity, nor is any sort of standard port scan, such as using nmap, or a simple ping, resolving with nslookup (although resolving required records is a pre-requisite), or other tools. The only reliable test is using Microsoft&amp;#39;s PortQry, which tests specific AD ports and the ephemeral ports, and the required responses from the services on the required AD ports it specifically scans for.&lt;/p&gt;
&lt;h2&gt;&lt;br /&gt;&lt;br /&gt;Let&amp;#39;s find out if the ports are being blocked&lt;/h2&gt;
&lt;p&gt;Now you&amp;#39;re thinking that your network infrastructure engineers know what they&amp;#39;re doing and opened up the necessary ports, so you&amp;#39;re thinking, this can&amp;#39;t be the reason? or is it? Well, let&amp;#39;s find out. We can use PortQry to test it. And no, you don&amp;#39;t want to use ping, nslookup, nmap or any other port scanner, because they&amp;#39;re not designed to query the necessary AD ports to see if they are responding or not. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;So let&amp;#39;s run PortQry&lt;/em&gt;&lt;/strong&gt;. If you get a &amp;quot;FILTERED&amp;quot; or &amp;quot;NOT LISTENING&amp;quot; in the results, well, that simply says the port is blocked. Download it and run it from each DC to other DCs in question, or from the bridgeheads in each site to the other bridgehead in the other site.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;Knock Knock Is That Port Open?&lt;br /&gt;By Mark Morowczynski [MSFT] 18 Apr 2011 3:22 PM&lt;br /&gt;Quick tutorial about PortQry GUI version.&lt;br /&gt;&lt;a href="http://blogs.technet.com/b/markmoro/archive/2011/04/18/knock-knock-is-that-port-open.aspx"&gt;http://blogs.technet.com/b/markmoro/archive/2011/04/18/knock-knock-is-that-port-open.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;PortQryUI - User Interface for the PortQry Command Line Port Scanner (GUI version)&lt;br /&gt;&lt;a href="http://www.microsoft.com/download/en/details.aspx?id=24009"&gt;http://www.microsoft.com/download/en/details.aspx?id=24009&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Download details: PortQry Command Line Port Scanner Version 2.0&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;a href="http://www.microsoft.com/downloads/en/details.aspx?familyid=89811747-c74b-4638-a2d5-ac828bdc6983&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/en/details.aspx?familyid=89811747-c74b-4638-a2d5-ac828bdc6983&amp;amp;displaylang=en&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;How to use Portqry to troubleshoot Active Directory connectivity issues&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/816103"&gt;http://support.microsoft.com/kb/816103&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Understanding portqry and the command&amp;#39;s output: New features and functionality in PortQry version 2.0 &lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/832919"&gt;http://support.microsoft.com/kb/832919&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Description of the Portqry.exe command-line utility&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/310099"&gt;http://support.microsoft.com/kb/310099&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Portqry Remarks &lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc759580(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/cc759580(WS.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;quot;At times you may see errors such as The RPC server is unavailable or There are no more endpoints available from the endpoint mapper ...&amp;quot;&lt;br /&gt;&lt;a href="http://blogs.technet.com/b/askds/archive/2009/01/22/using-portqry-for-troubleshooting.aspx"&gt;http://blogs.technet.com/b/askds/archive/2009/01/22/using-portqry-for-troubleshooting.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;&lt;br /&gt;Numerous ports must be opened.&lt;/h2&gt;
&lt;p&gt;That&amp;#39;s the simplest I can put it. However, the list of ports required is long, to the dismay of network infrastructure engineering teams that must bequest ports to allow AD to communicate, replicate, etc, these ports must be opened. There really isn&amp;#39;t much that can be done otherwise.&lt;/p&gt;
&lt;h3&gt;Here&amp;#39;s the list:&lt;/h3&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;
&lt;table width="536" cellpadding="0" cellspacing="0" border="0" style="width:403pt;border-collapse:collapse;"&gt;
&lt;colgroup&gt;&lt;col width="161" style="width:121pt;mso-width-source:userset;mso-width-alt:5888;"&gt;&lt;/col&gt;&lt;col width="194" style="width:146pt;mso-width-source:userset;mso-width-alt:7094;"&gt;&lt;/col&gt;&lt;col width="181" style="width:136pt;mso-width-source:userset;mso-width-alt:6619;"&gt;&lt;/col&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr style="height:16.5pt;"&gt;
&lt;td width="161" height="22" class="xl68" style="background-color:transparent;width:121pt;height:16.5pt;border:windowtext 1pt solid;"&gt;&lt;strong&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;Protocol and Port&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;td width="194" class="xl69" style="border-bottom:windowtext 1pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext 1pt solid;border-right:windowtext 1pt solid;"&gt;&lt;strong&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;AD and AD DS Usage&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;td width="181" class="xl72" style="border-bottom:windowtext 1pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext 1pt solid;border-right:windowtext 1pt solid;"&gt;&lt;strong&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;Type of traffic&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl90" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:#f0f0f0;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 25&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl92" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:#f0f0f0;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Replication&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl73" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:#f0f0f0;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;SMTP&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:45pt;"&gt;
&lt;td height="60" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:45pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 42&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;If using WINS in a domain trust scenario offering NetBIOS resolution&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;WINS&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 135&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Replication&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;RPC, EPM&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 137&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;NetBIOS Name resolution&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;NetBIOS Name resolution&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:30pt;"&gt;
&lt;td height="40" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:30pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 139&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;User and Computer Authentication, Replication&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;DFSN, NetBIOS Session Service, NetLogon&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:60pt;"&gt;
&lt;td height="80" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:60pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP and UDP 389&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Directory, Replication, User and Computer Authentication, Group Policy, Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;LDAP&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:60pt;"&gt;
&lt;td height="80" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:60pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 636&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Directory, Replication, User and Computer Authentication, Group Policy, Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;LDAP SSL&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:60pt;"&gt;
&lt;td height="80" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:60pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 3268&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Directory, Replication, User and Computer Authentication, Group Policy, Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;LDAP GC&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:60pt;"&gt;
&lt;td height="80" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:60pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 3269&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Directory, Replication, User and Computer Authentication, Group Policy, Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;LDAP GC SSL&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:45pt;"&gt;
&lt;td height="60" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:45pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP and UDP 88&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;User and Computer Authentication, Forest Level Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Kerberos&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:45pt;"&gt;
&lt;td height="60" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:45pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP and UDP 53&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;User and Computer Authentication, Name Resolution, Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;DNS&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:49.5pt;mso-height-source:userset;"&gt;
&lt;td height="66" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:49.5pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP and UDP 445&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Replication, User and Computer Authentication, Group Policy, Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;SMB, CIFS, SMB2, DFSN, LSARPC, NbtSS, NetLogonR, SamR, SrvSvc&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 9389&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;AD DS Web Services&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl75" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;SOAP&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 5722&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;File Replication&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl75" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;RPC, DFSR (SYSVOL)&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:45pt;"&gt;
&lt;td height="60" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:45pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP and UDP 464&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Replication, User and Computer Authentication, Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl75" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Kerberos change/set password&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;UDP 123&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Windows Time, Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl75" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Windows Time&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:30pt;"&gt;
&lt;td height="40" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:30pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;UDP 137&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;User and Computer Authentication&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl75" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;NetLogon, NetBIOS Name Resolution&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:30pt;"&gt;
&lt;td height="40" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:30pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;UDP 138&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;DFS, Group Policy, NetBIOS Netlogon, Browsing&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl75" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;DFSN, NetLogon, NetBIOS Datagram Service&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:75.75pt;mso-height-source:userset;"&gt;
&lt;td height="101" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:75.75pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;UDP 67 and UDP 2535&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;DHCP (Note: DHCP is not a core AD DS service but these ports may be necessary for other functions besides DHCP, such as WDS)&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;DHCP, MADCAP, PXE&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl67" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15.75pt;"&gt;
&lt;td height="21" class="xl81" style="border-bottom:#f0f0f0;border-left:windowtext 1pt solid;background-color:transparent;height:15.75pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Ephemeral Ports:&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;td width="194" class="xl82" style="border-bottom:#f0f0f0;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl83" style="border-bottom:#f0f0f0;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:154.5pt;mso-height-source:userset;"&gt;
&lt;td colspan="3" width="536" height="206" class="xl85" style="border-bottom:windowtext 1pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:403pt;height:154.5pt;border-top:windowtext 1pt solid;border-right:black 1pt solid;"&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;And most of all, the Ephemeral ports, or also known as the &amp;quot;service response ports,&amp;quot; that are required for communications. These ports are dynamically created for session responses for each client that establishes a session, (no matter what the &amp;#39;client&amp;#39; may be), and not only to Windows, but to Linux and Unix as well. See below in the references section to find out more on what &amp;#39;ephemeral&amp;#39; means.are used only for that session. Once the session has dissolved, the ports are put back into the pool for reuse. This applies not only to Windows, but to Linux and Unix as well. See below in the references section to find out more on what &amp;#39;ephemeral&amp;#39; means.&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:30pt;"&gt;
&lt;td width="161" height="40" class="xl94" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:121pt;height:30pt;border-top:#f0f0f0;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP &amp;amp; UDP 1025-5000&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl88" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:#f0f0f0;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Window 2003/XP and older&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl84" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:#f0f0f0;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Ephemeral Dynamic Service Response Ports&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td width="161" height="20" class="xl94" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:121pt;height:15pt;border-top:#f0f0f0;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl88" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:#f0f0f0;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl84" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:#f0f0f0;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:30pt;"&gt;
&lt;td width="161" height="40" class="xl95" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:121pt;height:30pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP &amp;amp; UDP 49152-65535&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl89" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Windows 2008/Vista and newer&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl76" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Ephemeral Dynamic Service Response Ports&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td width="161" height="20" class="xl95" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:121pt;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl89" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:49.5pt;mso-height-source:userset;"&gt;
&lt;td width="161" height="66" class="xl95" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:121pt;height:49.5pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP Dynamic Ephemeral&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl89" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Replication, User and Computer Authentication, Group Policy, Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl76" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;RPC, DCOM, EPM, DRSUAPI, NetLogonR, SamR, FRS&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td width="161" height="20" class="xl95" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:121pt;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:32.25pt;mso-height-source:userset;"&gt;
&lt;td width="161" height="43" class="xl95" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:121pt;height:32.25pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;UDP Dynamic Ephermeral&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Group Policy&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl75" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;DCOM, RPC, EPM&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl67" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:39pt;mso-height-source:userset;"&gt;
&lt;td colspan="3" width="536" height="52" class="xl78" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:403pt;height:39pt;border-top:windowtext 0.5pt solid;border-right:black 1pt solid;"&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;If the scenario is a Mixed-Mode NT4 &amp;amp; Active Directory scenario with NT4 BDCs, then the following must be opened:&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:45.75pt;"&gt;
&lt;td height="61" class="xl65" style="border-bottom:windowtext 1pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:45.75pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP &amp;amp; UDP 1024 - 65535&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl71" style="border-bottom:windowtext 1pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;NT4 BDC to Windows 2000 or newer Domain controller PDC-E communications&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl77" style="border-bottom:windowtext 1pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;RPC, LSA RPC, LDAP, LDAP SSL, LDAP GC, LDAP GC SSL, DNS, Kerberos, SMB&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;See, wasn&amp;#39;t that simple?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;The Short list without port explanations:&lt;/h3&gt;
&lt;h2&gt;
&lt;table width="192" cellpadding="0" cellspacing="0" border="0" style="width:144pt;border-collapse:collapse;"&gt;
&lt;colgroup&gt;&lt;col width="101" style="width:76pt;mso-width-source:userset;mso-width-alt:3693;"&gt;&lt;/col&gt;&lt;col width="91" style="width:68pt;mso-width-source:userset;mso-width-alt:3328;"&gt;&lt;/col&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr style="height:16.5pt;"&gt;
&lt;td width="101" height="22" class="xl74" style="background-color:transparent;width:76pt;height:16.5pt;border:windowtext 1pt solid;"&gt;&lt;strong&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Protocol&lt;/span&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;td width="91" class="xl75" style="border-bottom:windowtext 1pt solid;border-left:windowtext;background-color:transparent;width:68pt;border-top:windowtext 1pt solid;border-right:windowtext 1pt solid;"&gt;&lt;strong&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Port&lt;/span&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl68" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl69" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;25&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;42&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;135&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;137&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15.75pt;"&gt;
&lt;td height="21" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15.75pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;139&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP and UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;389&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;636&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;3268&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;3269&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP and UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;88&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP and UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;53&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP and UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;445&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;9389&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;5722&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP and UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;464&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;123&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;137&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;138&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;67&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;2535&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP &amp;amp; UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;1025-5000&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15.75pt;"&gt;
&lt;td height="21" class="xl71" style="border-bottom:windowtext 1pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15.75pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP &amp;amp; UDP&lt;/td&gt;
&lt;td class="xl64" style="border-bottom:windowtext 1pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;49152-65535&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15.75pt;"&gt;
&lt;td height="21" class="xl66" style="border-bottom:#f0f0f0;border-left:windowtext 1pt solid;background-color:transparent;height:15.75pt;border-top:#f0f0f0;border-right:#f0f0f0;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td class="xl67" style="border-bottom:#f0f0f0;border-left:#f0f0f0;background-color:transparent;border-top:#f0f0f0;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:66.75pt;mso-height-source:userset;"&gt;
&lt;td colspan="2" width="192" height="89" class="xl76" style="border-bottom:windowtext 1pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:144pt;height:66.75pt;border-top:windowtext 1pt solid;border-right:black 1pt solid;"&gt;&lt;strong&gt;If the scenario is a Mixed-Mode NT4 &amp;amp; Active Directory scenario with NT4 BDCs, then the following must be opened:&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15.75pt;"&gt;
&lt;td height="21" class="xl72" style="border-bottom:windowtext 1pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15.75pt;border-top:windowtext;border-right:#f0f0f0;"&gt;TCP &amp;amp; UDP&lt;/td&gt;
&lt;td class="xl73" style="border-bottom:windowtext 1pt solid;border-left:#f0f0f0;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;1024-65535&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/h2&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;&lt;br /&gt;Restricting Firewall ports&lt;/h2&gt;
&lt;p&gt;And yes, you can choose to restrict the port ranges to specific ports, and if choosing this option, you must specifically specify the correct ports for the correct service.&lt;/p&gt;
&lt;p&gt;It depends on what ports and services you want to restrict?&lt;/p&gt;
&lt;p&gt;1. Method 1&lt;br /&gt;This is to used to set the specific AD replication port. By default it uses dynamic port to replicate data from DC in one site to another. &lt;br /&gt;This is applicable for restriction AD replication to a specific port range. Procedure:&lt;br /&gt;&amp;nbsp;Modify registry to select a static port.&lt;br /&gt;&amp;nbsp;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters&lt;br /&gt;&amp;nbsp;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters&lt;/p&gt;
&lt;p&gt;Restricting Active Directory replication traffic and client RPC traffic to a specific port&lt;br /&gt;&amp;nbsp;&lt;a href="http://support.microsoft.com/kb/224196"&gt;http://support.microsoft.com/kb/224196&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;2. Method 2&lt;br /&gt;This is for configuring the port range(s) in the&amp;nbsp;Windows Firewall. &lt;br /&gt;&amp;nbsp;Netsh - use the following examples to set a starting port range, and number of ports after it to use&lt;br /&gt;&amp;nbsp;netsh int ipv4 set dynamicport tcp start=10000 num=1000&lt;br /&gt;&amp;nbsp;netsh int ipv4 set dynamicport udp start=10000 num=1000&lt;/p&gt;
&lt;p&gt;The default dynamic port range for TCP/IP has changed in Windows Vista and in Windows Server 2008&lt;br /&gt;&amp;nbsp;&lt;a href="http://support.microsoft.com/kb/929851"&gt;http://support.microsoft.com/kb/929851&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;3. Modify the registry &lt;br /&gt;This is for WIndows services communications. It also affects AD communications.&lt;br /&gt;&amp;nbsp;HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc&lt;/p&gt;
&lt;p&gt;How to configure RPC dynamic port allocation to work with firewalls &lt;br /&gt;&amp;nbsp;&lt;a href="http://support.microsoft.com/kb/154596/en-us"&gt;http://support.microsoft.com/kb/154596/en-us&lt;/a&gt; &lt;/p&gt;
&lt;h2&gt;&lt;/h2&gt;
&lt;h2&gt;&lt;/h2&gt;
&lt;h2&gt;&lt;br /&gt;Here are some related links to restricting AD replication ports.&lt;/h2&gt;
&lt;p&gt;Reference thread:&lt;br /&gt;&lt;a href="http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/76e8654a-fbba-49af-b6d6-e8d9d127bf03/"&gt;http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/76e8654a-fbba-49af-b6d6-e8d9d127bf03/&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;RODC Firewall Port Requirements&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/dd772723(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/dd772723(WS.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Active Directory Replication over Firewalls &lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/bb727063.aspx"&gt;http://technet.microsoft.com/en-us/library/bb727063.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;&lt;br /&gt;&lt;br /&gt;RODC - &amp;quot;Read only Domain Controllers&amp;quot; have their own port requirements:&lt;/h2&gt;
&lt;p&gt;
&lt;table width="233" cellpadding="0" cellspacing="0" border="0" style="width:175pt;border-collapse:collapse;"&gt;
&lt;colgroup&gt;&lt;col width="107" style="width:80pt;mso-width-source:userset;mso-width-alt:3913;"&gt;&lt;/col&gt;&lt;col width="126" style="width:95pt;mso-width-source:userset;mso-width-alt:4608;"&gt;&lt;/col&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr style="height:16.5pt;"&gt;
&lt;td width="107" height="22" class="xl65" style="background-color:transparent;width:80pt;height:16.5pt;border:windowtext 1pt solid;"&gt;&lt;strong&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Port&lt;/span&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;td width="126" class="xl66" style="border-bottom:windowtext 1pt solid;border-left:#f0f0f0;background-color:transparent;width:95pt;border-top:windowtext 1pt solid;border-right:windowtext 1pt solid;"&gt;&lt;strong&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Type of Traffic&lt;/span&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl71" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:#f0f0f0;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;UDP 53 DNS&lt;/span&gt;&lt;/td&gt;
&lt;td class="xl72" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:#f0f0f0;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;DNS&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl67" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 53 DNS&lt;/span&gt;&lt;/td&gt;
&lt;td class="xl68" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;DNS&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl67" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;TCP 135&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td class="xl68" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;RPC, EPM&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl67" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;TCP Static 53248&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td class="xl68" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;FRsRpc&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15.75pt;"&gt;
&lt;td height="21" class="xl69" style="border-bottom:windowtext 1pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15.75pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;TCP 389&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td class="xl70" style="border-bottom:windowtext 1pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;LDAP&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;br /&gt;Designing RODCs in the Perimeter Network&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/dd728028(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/dd728028(WS.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Restricting Active Directory replication traffic and client RPC traffic to a specific port&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/224196"&gt;http://support.microsoft.com/kb/224196&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Good discussion on RODC and firewall ports required:&lt;br /&gt;&lt;a href="http://forums.techarena.in/active-directory/1303925.htm"&gt;http://forums.techarena.in/active-directory/1303925.htm&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Further info on how RODC authentication works will help understand the ports:&lt;br /&gt;Understanding &amp;ldquo;Read Only Domain Controller&amp;rdquo; authentication &lt;br /&gt;&lt;a href="http://blogs.technet.com/b/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx"&gt;http://blogs.technet.com/b/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;&lt;br /&gt;References&lt;/h2&gt;
&lt;p&gt;How to configure a firewall for domains and trusts&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/179442"&gt;http://support.microsoft.com/kb/179442&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Active Directory and Active Directory Domain Services Port Requirements, Updated: June 18, 2009 (includes updated new ephemeral ports for Windows Vista/2008 and newer). This also discusses RODC port requirements. You must also make sure the ephemeral ports are opened. They are:&lt;br /&gt;&amp;nbsp;&amp;nbsp; TCP &amp;amp; UDP 1025-5000&lt;br /&gt;&amp;nbsp;&amp;nbsp; TCP &amp;amp; UDP 49152-65535&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/dd772723(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/dd772723(WS.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Windows 2008, 2008 R2, Vista and Windows 7 Ephermeral Port range has changed from the ports used by Windows 2003 Windows XP, and Windows 2000. Default ephemeral (Random service dynamic response ports) are UDP 1024 - 65535 (See KB179442 below), but for Vista and Windows 2008 it&amp;#39;s different. Their default start port range is UDP 49152 to UDP 65535 (see KB929851 below).&lt;/p&gt;
&lt;p&gt;Quoted from KB929851 (link posted below): &amp;quot;To comply with Internet Assigned Numbers Authority (IANA) recommendations, Microsoft has increased the dynamic client port range for outgoing connections in Windows Vista and in Windows Server 2008. The new default start port is 49152, and the default end port is 65535. This is a change from the configuration of earlier versions of Microsoft Windows that used a default port range of 1025 through 5000.&amp;quot; &lt;/p&gt;
&lt;p&gt;Windows Vista, Windows 7, Windows 2008 and Windows 2008 R2 Service Response Ports (ephemeral ports) have changed.&lt;br /&gt;&lt;a href="http://support.microsoft.com/?kbid=929851"&gt;http://support.microsoft.com/?kbid=929851&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Active Directory and Firewall Ports - I found it hard to find a definitive list on the internet for what ports needed opening for Active Directory to replication between Firewalls. ... &lt;br /&gt;&lt;a href="http://geekswithblogs.net/TSCustomiser/archive/2007/05/09/112357.aspx"&gt;http://geekswithblogs.net/TSCustomiser/archive/2007/05/09/112357.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Active Directory Replication over Firewalls, Jan 31, 2006. (includes older pre-Windows Vista/2008 ephemeral ports) &lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/bb727063.aspx"&gt;http://technet.microsoft.com/en-us/library/bb727063.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;How Domains and Forests Work&lt;br /&gt;Also shows a list of ports needed.&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc783351(v=ws.10).aspx"&gt;http://technet.microsoft.com/en-us/library/cc783351(v=ws.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Paul Bergson&amp;#39;s Blog on AD Replication and Firewall Ports&lt;br /&gt;&lt;a href="http://www.pbbergs.com/windows/articles/FirewallReplication.html"&gt;http://www.pbbergs.com/windows/articles/FirewallReplication.html&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;&lt;br /&gt;Exchange DS Access ports&lt;/h2&gt;
&lt;p&gt;Configuring an Intranet Firewall for Exchange 2003, April 14, 2006. &lt;br /&gt;Protocol ports required for the intranet firewall and ports required for Active Directory and Kerberos communications &lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/bb125069.aspx"&gt;http://technet.microsoft.com/en-us/library/bb125069.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;Additonal Reading&lt;/h2&gt;
&lt;p&gt;Restricting Active Directory replication traffic and client RPC ...Restricting Active Directory replication traffic and client RPC traffic to a ... unique port, and you restart the Netlogon service on the domain controller. ...&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/224196"&gt;http://support.microsoft.com/kb/224196&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;How to restrict FRS replication traffic to a specific static port - How to restrict FRS replication traffic to a specific static port ... Windows 2000-based domain controllers and servers use FRS to replicate system policy ...&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/319553"&gt;http://support.microsoft.com/kb/319553&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Some firewalls may reject network traffic that originates from Windows Server 2003 Service Pack 1-based or Windows Vista-based computers&lt;br /&gt;This KB indicates Checkpoint firewalls having an issue with AD communications.&lt;br /&gt;&lt;a href="http://support.microsoft.com/?kbid=899148"&gt;http://support.microsoft.com/?kbid=899148&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;Checkpoint Firewall and AD, DNS and RPC Communications and Replication traffic&lt;/h2&gt;
&lt;p&gt;Checkpoint firewalls have a known issue if you are running version R55 or older. You will need to make a registry entry to allows traffic to flow between the 2 sites via the vpn. The preferred solution is to upgrade the Checkpoint firewall.&lt;/p&gt;
&lt;h3&gt;More info:&lt;/h3&gt;
&lt;p&gt;Some firewalls may reject network traffic that originates from Windows Server 2003 Service Pack 1-based or Windows Vista-based computers&lt;br /&gt;(This link relates to and helps resolve the Checkpoint issue)&lt;br /&gt;&lt;a href="http://support.microsoft.com/?kbid=899148"&gt;http://support.microsoft.com/?kbid=899148&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Note from one poster on the internet with a Checkpoint firewall:&lt;br /&gt;For Windows 2003 R2 and non-R2 remote domain controller we added the Server2003NegotiateDisable entry in &lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Rpc&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;I know you&amp;#39;ve enjoyed reading this. Well, whether you did or not, at least you now know what to do to make it work.&lt;/h3&gt;
&lt;p&gt;Comments, suggestions and corrections are welcomed!&lt;/p&gt;
&lt;h3&gt;Ace Fekay&lt;/h3&gt;</description></item></channel></rss>