<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Search results for 'app:weblogs' matching tags 'dcpromo' and 'NTFRS Errors'</title><link>http://msmvps.com/search/SearchResults.aspx?q=app:weblogs&amp;tag=dcpromo,NTFRS+Errors&amp;orTags=0&amp;o=DateDescending</link><description>Search results for 'app:weblogs' matching tags 'dcpromo' and 'NTFRS Errors'</description><dc:language>en-US</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Active Directory Firewall Ports - Let's Try To Make This Simple</title><link>http://msmvps.com/blogs/acefekay/archive/2011/11/01/active-directory-firewall-ports-let-s-try-to-make-this-simple.aspx</link><pubDate>Tue, 01 Nov 2011 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1801962</guid><dc:creator>acefekay</dc:creator><description>&lt;p&gt;Ace Fekay, MCT, MVP, MCITP EA, MCTS Windows 2008, Exchange 2007 &amp;amp; Exchange 2010, Exchange 2010 Enterprise Administrator, MCSE 2003/2000, MCSA Messaging 2003&lt;br /&gt;Microsoft Certified Trainer&lt;br /&gt;Microsoft MVP: Directory Services&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;Original Publication Date: 11/1/2011&lt;br /&gt;Port Matrix Table Resized to fit in browser - 12/7/2011&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;&lt;/h2&gt;
&lt;h2&gt;RPC server not available?&lt;br /&gt;Replication errors in the Event viewer?&lt;/h2&gt;
&lt;h4&gt;Sound familiar?&lt;/h4&gt;
&lt;p&gt;If so, you&amp;#39;ve been succumbed to the fact and realization there are possibly necessary ports being blocked causing these errors. Whether between locations with firewall/VPN tunnel port blocks, Windows Firewall (which is usually not the culprit), or even security software or antivirus apps with some sort of &amp;quot;network traffic protection&amp;quot; feature enabled that is causing the problems. &lt;/p&gt;
&lt;p&gt;Simply speaking, if there are replication or other AD communication problems, and you have an antivirus software installed on the endpoints or installed on all of&amp;nbsp; your DCs, disable it, or better yet, uninstall it. Uninstalling it is the best bet, so you know tehre are no traces of other subcomponents that are active that may still be causing the block. If after uninstalling it, and you find replication now works, well there you have it. At that point, you&amp;#39;ll need to contact your antivirus vendor to ask them the best way to configure it to allow AD communications and replication.&lt;/p&gt;
&lt;p&gt;If it&amp;#39;s not your antivirus or security app, and disabling the Windows firewall doesn&amp;#39;t do the trick, then it&amp;#39;s obvious it&amp;#39;s an outside factor - your firewalls.&lt;/p&gt;
&lt;p&gt;Also to point out, when testing for port blocks, tools such as telnet is not a good tool to test AD/DC to DC connectivity, nor is any sort of standard port scan, such as using nmap, or a simple ping, resolving with nslookup (although resolving required records is a pre-requisite), or other tools. The only reliable test is using Microsoft&amp;#39;s PortQry, which tests specific AD ports and the ephemeral ports, and the required responses from the services on the required AD ports it specifically scans for.&lt;/p&gt;
&lt;h2&gt;&lt;br /&gt;&lt;br /&gt;Let&amp;#39;s find out if the ports are being blocked&lt;/h2&gt;
&lt;p&gt;Now you&amp;#39;re thinking that your network infrastructure engineers know what they&amp;#39;re doing and opened up the necessary ports, so you&amp;#39;re thinking, this can&amp;#39;t be the reason? or is it? Well, let&amp;#39;s find out. We can use PortQry to test it. And no, you don&amp;#39;t want to use ping, nslookup, nmap or any other port scanner, because they&amp;#39;re not designed to query the necessary AD ports to see if they are responding or not. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;So let&amp;#39;s run PortQry&lt;/em&gt;&lt;/strong&gt;. If you get a &amp;quot;FILTERED&amp;quot; or &amp;quot;NOT LISTENING&amp;quot; in the results, well, that simply says the port is blocked. Download it and run it from each DC to other DCs in question, or from the bridgeheads in each site to the other bridgehead in the other site.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;Knock Knock Is That Port Open?&lt;br /&gt;By Mark Morowczynski [MSFT] 18 Apr 2011 3:22 PM&lt;br /&gt;Quick tutorial about PortQry GUI version.&lt;br /&gt;&lt;a href="http://blogs.technet.com/b/markmoro/archive/2011/04/18/knock-knock-is-that-port-open.aspx"&gt;http://blogs.technet.com/b/markmoro/archive/2011/04/18/knock-knock-is-that-port-open.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;PortQryUI - User Interface for the PortQry Command Line Port Scanner (GUI version)&lt;br /&gt;&lt;a href="http://www.microsoft.com/download/en/details.aspx?id=24009"&gt;http://www.microsoft.com/download/en/details.aspx?id=24009&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Download details: PortQry Command Line Port Scanner Version 2.0&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;a href="http://www.microsoft.com/downloads/en/details.aspx?familyid=89811747-c74b-4638-a2d5-ac828bdc6983&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/en/details.aspx?familyid=89811747-c74b-4638-a2d5-ac828bdc6983&amp;amp;displaylang=en&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;How to use Portqry to troubleshoot Active Directory connectivity issues&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/816103"&gt;http://support.microsoft.com/kb/816103&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Understanding portqry and the command&amp;#39;s output: New features and functionality in PortQry version 2.0 &lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/832919"&gt;http://support.microsoft.com/kb/832919&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Description of the Portqry.exe command-line utility&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/310099"&gt;http://support.microsoft.com/kb/310099&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Portqry Remarks &lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc759580(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/cc759580(WS.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;quot;At times you may see errors such as The RPC server is unavailable or There are no more endpoints available from the endpoint mapper ...&amp;quot;&lt;br /&gt;&lt;a href="http://blogs.technet.com/b/askds/archive/2009/01/22/using-portqry-for-troubleshooting.aspx"&gt;http://blogs.technet.com/b/askds/archive/2009/01/22/using-portqry-for-troubleshooting.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;&lt;br /&gt;Numerous ports must be opened.&lt;/h2&gt;
&lt;p&gt;That&amp;#39;s the simplest I can put it. However, the list of ports required is long, to the dismay of network infrastructure engineering teams that must bequest ports to allow AD to communicate, replicate, etc, these ports must be opened. There really isn&amp;#39;t much that can be done otherwise.&lt;/p&gt;
&lt;h3&gt;Here&amp;#39;s the list:&lt;/h3&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;
&lt;table width="536" cellpadding="0" cellspacing="0" border="0" style="width:403pt;border-collapse:collapse;"&gt;
&lt;colgroup&gt;&lt;col width="161" style="width:121pt;mso-width-source:userset;mso-width-alt:5888;"&gt;&lt;/col&gt;&lt;col width="194" style="width:146pt;mso-width-source:userset;mso-width-alt:7094;"&gt;&lt;/col&gt;&lt;col width="181" style="width:136pt;mso-width-source:userset;mso-width-alt:6619;"&gt;&lt;/col&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr style="height:16.5pt;"&gt;
&lt;td width="161" height="22" class="xl68" style="background-color:transparent;width:121pt;height:16.5pt;border:windowtext 1pt solid;"&gt;&lt;strong&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;Protocol and Port&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;td width="194" class="xl69" style="border-bottom:windowtext 1pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext 1pt solid;border-right:windowtext 1pt solid;"&gt;&lt;strong&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;AD and AD DS Usage&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;td width="181" class="xl72" style="border-bottom:windowtext 1pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext 1pt solid;border-right:windowtext 1pt solid;"&gt;&lt;strong&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;Type of traffic&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl90" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:#f0f0f0;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 25&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl92" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:#f0f0f0;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Replication&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl73" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:#f0f0f0;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;SMTP&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:45pt;"&gt;
&lt;td height="60" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:45pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 42&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;If using WINS in a domain trust scenario offering NetBIOS resolution&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;WINS&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 135&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Replication&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;RPC, EPM&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 137&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;NetBIOS Name resolution&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;NetBIOS Name resolution&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:30pt;"&gt;
&lt;td height="40" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:30pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 139&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;User and Computer Authentication, Replication&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;DFSN, NetBIOS Session Service, NetLogon&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:60pt;"&gt;
&lt;td height="80" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:60pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP and UDP 389&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Directory, Replication, User and Computer Authentication, Group Policy, Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;LDAP&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:60pt;"&gt;
&lt;td height="80" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:60pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 636&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Directory, Replication, User and Computer Authentication, Group Policy, Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;LDAP SSL&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:60pt;"&gt;
&lt;td height="80" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:60pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 3268&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Directory, Replication, User and Computer Authentication, Group Policy, Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;LDAP GC&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:60pt;"&gt;
&lt;td height="80" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:60pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 3269&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Directory, Replication, User and Computer Authentication, Group Policy, Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;LDAP GC SSL&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:45pt;"&gt;
&lt;td height="60" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:45pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP and UDP 88&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;User and Computer Authentication, Forest Level Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Kerberos&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:45pt;"&gt;
&lt;td height="60" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:45pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP and UDP 53&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;User and Computer Authentication, Name Resolution, Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;DNS&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:49.5pt;mso-height-source:userset;"&gt;
&lt;td height="66" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:49.5pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP and UDP 445&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Replication, User and Computer Authentication, Group Policy, Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;SMB, CIFS, SMB2, DFSN, LSARPC, NbtSS, NetLogonR, SamR, SrvSvc&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 9389&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;AD DS Web Services&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl75" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;SOAP&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 5722&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;File Replication&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl75" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;RPC, DFSR (SYSVOL)&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:45pt;"&gt;
&lt;td height="60" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:45pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP and UDP 464&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Replication, User and Computer Authentication, Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl75" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Kerberos change/set password&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;UDP 123&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Windows Time, Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl75" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Windows Time&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:30pt;"&gt;
&lt;td height="40" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:30pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;UDP 137&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;User and Computer Authentication&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl75" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;NetLogon, NetBIOS Name Resolution&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:30pt;"&gt;
&lt;td height="40" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:30pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;UDP 138&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;DFS, Group Policy, NetBIOS Netlogon, Browsing&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl75" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;DFSN, NetLogon, NetBIOS Datagram Service&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="mso-spacerun:yes;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:75.75pt;mso-height-source:userset;"&gt;
&lt;td height="101" class="xl91" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:75.75pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;UDP 67 and UDP 2535&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl93" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;DHCP (Note: DHCP is not a core AD DS service but these ports may be necessary for other functions besides DHCP, such as WDS)&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;DHCP, MADCAP, PXE&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl67" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15.75pt;"&gt;
&lt;td height="21" class="xl81" style="border-bottom:#f0f0f0;border-left:windowtext 1pt solid;background-color:transparent;height:15.75pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Ephemeral Ports:&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;td width="194" class="xl82" style="border-bottom:#f0f0f0;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl83" style="border-bottom:#f0f0f0;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:154.5pt;mso-height-source:userset;"&gt;
&lt;td colspan="3" width="536" height="206" class="xl85" style="border-bottom:windowtext 1pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:403pt;height:154.5pt;border-top:windowtext 1pt solid;border-right:black 1pt solid;"&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;And most of all, the Ephemeral ports, or also known as the &amp;quot;service response ports,&amp;quot; that are required for communications. These ports are dynamically created for session responses for each client that establishes a session, (no matter what the &amp;#39;client&amp;#39; may be), and not only to Windows, but to Linux and Unix as well. See below in the references section to find out more on what &amp;#39;ephemeral&amp;#39; means.are used only for that session. Once the session has dissolved, the ports are put back into the pool for reuse. This applies not only to Windows, but to Linux and Unix as well. See below in the references section to find out more on what &amp;#39;ephemeral&amp;#39; means.&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:30pt;"&gt;
&lt;td width="161" height="40" class="xl94" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:121pt;height:30pt;border-top:#f0f0f0;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP &amp;amp; UDP 1025-5000&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl88" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:#f0f0f0;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Window 2003/XP and older&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl84" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:#f0f0f0;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Ephemeral Dynamic Service Response Ports&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td width="161" height="20" class="xl94" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:121pt;height:15pt;border-top:#f0f0f0;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl88" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:#f0f0f0;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl84" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:#f0f0f0;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:30pt;"&gt;
&lt;td width="161" height="40" class="xl95" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:121pt;height:30pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP &amp;amp; UDP 49152-65535&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl89" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Windows 2008/Vista and newer&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl76" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Ephemeral Dynamic Service Response Ports&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td width="161" height="20" class="xl95" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:121pt;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl89" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:49.5pt;mso-height-source:userset;"&gt;
&lt;td width="161" height="66" class="xl95" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:121pt;height:49.5pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP Dynamic Ephemeral&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl89" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Replication, User and Computer Authentication, Group Policy, Trusts&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl76" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;RPC, DCOM, EPM, DRSUAPI, NetLogonR, SamR, FRS&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td width="161" height="20" class="xl95" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:121pt;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:32.25pt;mso-height-source:userset;"&gt;
&lt;td width="161" height="43" class="xl95" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:121pt;height:32.25pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;UDP Dynamic Ephermeral&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Group Policy&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl75" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;DCOM, RPC, EPM&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl67" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl74" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:39pt;mso-height-source:userset;"&gt;
&lt;td colspan="3" width="536" height="52" class="xl78" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:403pt;height:39pt;border-top:windowtext 0.5pt solid;border-right:black 1pt solid;"&gt;&lt;strong&gt;&lt;em&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;If the scenario is a Mixed-Mode NT4 &amp;amp; Active Directory scenario with NT4 BDCs, then the following must be opened:&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:45.75pt;"&gt;
&lt;td height="61" class="xl65" style="border-bottom:windowtext 1pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:45.75pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP &amp;amp; UDP 1024 - 65535&lt;/span&gt;&lt;/td&gt;
&lt;td width="194" class="xl71" style="border-bottom:windowtext 1pt solid;border-left:windowtext;background-color:transparent;width:146pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;NT4 BDC to Windows 2000 or newer Domain controller PDC-E communications&lt;/span&gt;&lt;/td&gt;
&lt;td width="181" class="xl77" style="border-bottom:windowtext 1pt solid;border-left:windowtext;background-color:transparent;width:136pt;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;RPC, LSA RPC, LDAP, LDAP SSL, LDAP GC, LDAP GC SSL, DNS, Kerberos, SMB&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;See, wasn&amp;#39;t that simple?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;The Short list without port explanations:&lt;/h3&gt;
&lt;h2&gt;
&lt;table width="192" cellpadding="0" cellspacing="0" border="0" style="width:144pt;border-collapse:collapse;"&gt;
&lt;colgroup&gt;&lt;col width="101" style="width:76pt;mso-width-source:userset;mso-width-alt:3693;"&gt;&lt;/col&gt;&lt;col width="91" style="width:68pt;mso-width-source:userset;mso-width-alt:3328;"&gt;&lt;/col&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr style="height:16.5pt;"&gt;
&lt;td width="101" height="22" class="xl74" style="background-color:transparent;width:76pt;height:16.5pt;border:windowtext 1pt solid;"&gt;&lt;strong&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Protocol&lt;/span&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;td width="91" class="xl75" style="border-bottom:windowtext 1pt solid;border-left:windowtext;background-color:transparent;width:68pt;border-top:windowtext 1pt solid;border-right:windowtext 1pt solid;"&gt;&lt;strong&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Port&lt;/span&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl68" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl69" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;25&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;42&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;135&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;137&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15.75pt;"&gt;
&lt;td height="21" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15.75pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;139&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP and UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;389&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;636&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;3268&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;3269&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP and UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;88&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP and UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;53&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP and UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;445&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;9389&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;5722&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP and UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;464&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;123&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;137&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;138&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;67&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;2535&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl70" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP &amp;amp; UDP&lt;/td&gt;
&lt;td class="xl65" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;1025-5000&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15.75pt;"&gt;
&lt;td height="21" class="xl71" style="border-bottom:windowtext 1pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15.75pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;TCP &amp;amp; UDP&lt;/td&gt;
&lt;td class="xl64" style="border-bottom:windowtext 1pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;49152-65535&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15.75pt;"&gt;
&lt;td height="21" class="xl66" style="border-bottom:#f0f0f0;border-left:windowtext 1pt solid;background-color:transparent;height:15.75pt;border-top:#f0f0f0;border-right:#f0f0f0;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;td class="xl67" style="border-bottom:#f0f0f0;border-left:#f0f0f0;background-color:transparent;border-top:#f0f0f0;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:66.75pt;mso-height-source:userset;"&gt;
&lt;td colspan="2" width="192" height="89" class="xl76" style="border-bottom:windowtext 1pt solid;border-left:windowtext 1pt solid;background-color:transparent;width:144pt;height:66.75pt;border-top:windowtext 1pt solid;border-right:black 1pt solid;"&gt;&lt;strong&gt;If the scenario is a Mixed-Mode NT4 &amp;amp; Active Directory scenario with NT4 BDCs, then the following must be opened:&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15.75pt;"&gt;
&lt;td height="21" class="xl72" style="border-bottom:windowtext 1pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15.75pt;border-top:windowtext;border-right:#f0f0f0;"&gt;TCP &amp;amp; UDP&lt;/td&gt;
&lt;td class="xl73" style="border-bottom:windowtext 1pt solid;border-left:#f0f0f0;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;1024-65535&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/h2&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;&lt;br /&gt;Restricting Firewall ports&lt;/h2&gt;
&lt;p&gt;And yes, you can choose to restrict the port ranges to specific ports, and if choosing this option, you must specifically specify the correct ports for the correct service.&lt;/p&gt;
&lt;p&gt;It depends on what ports and services you want to restrict?&lt;/p&gt;
&lt;p&gt;1. Method 1&lt;br /&gt;This is to used to set the specific AD replication port. By default it uses dynamic port to replicate data from DC in one site to another. &lt;br /&gt;This is applicable for restriction AD replication to a specific port range. Procedure:&lt;br /&gt;&amp;nbsp;Modify registry to select a static port.&lt;br /&gt;&amp;nbsp;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters&lt;br /&gt;&amp;nbsp;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters&lt;/p&gt;
&lt;p&gt;Restricting Active Directory replication traffic and client RPC traffic to a specific port&lt;br /&gt;&amp;nbsp;&lt;a href="http://support.microsoft.com/kb/224196"&gt;http://support.microsoft.com/kb/224196&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;2. Method 2&lt;br /&gt;This is for configuring the port range(s) in the&amp;nbsp;Windows Firewall. &lt;br /&gt;&amp;nbsp;Netsh - use the following examples to set a starting port range, and number of ports after it to use&lt;br /&gt;&amp;nbsp;netsh int ipv4 set dynamicport tcp start=10000 num=1000&lt;br /&gt;&amp;nbsp;netsh int ipv4 set dynamicport udp start=10000 num=1000&lt;/p&gt;
&lt;p&gt;The default dynamic port range for TCP/IP has changed in Windows Vista and in Windows Server 2008&lt;br /&gt;&amp;nbsp;&lt;a href="http://support.microsoft.com/kb/929851"&gt;http://support.microsoft.com/kb/929851&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;3. Modify the registry &lt;br /&gt;This is for WIndows services communications. It also affects AD communications.&lt;br /&gt;&amp;nbsp;HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc&lt;/p&gt;
&lt;p&gt;How to configure RPC dynamic port allocation to work with firewalls &lt;br /&gt;&amp;nbsp;&lt;a href="http://support.microsoft.com/kb/154596/en-us"&gt;http://support.microsoft.com/kb/154596/en-us&lt;/a&gt; &lt;/p&gt;
&lt;h2&gt;&lt;/h2&gt;
&lt;h2&gt;&lt;/h2&gt;
&lt;h2&gt;&lt;br /&gt;Here are some related links to restricting AD replication ports.&lt;/h2&gt;
&lt;p&gt;Reference thread:&lt;br /&gt;&lt;a href="http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/76e8654a-fbba-49af-b6d6-e8d9d127bf03/"&gt;http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/76e8654a-fbba-49af-b6d6-e8d9d127bf03/&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;RODC Firewall Port Requirements&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/dd772723(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/dd772723(WS.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Active Directory Replication over Firewalls &lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/bb727063.aspx"&gt;http://technet.microsoft.com/en-us/library/bb727063.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;&lt;br /&gt;&lt;br /&gt;RODC - &amp;quot;Read only Domain Controllers&amp;quot; have their own port requirements:&lt;/h2&gt;
&lt;p&gt;
&lt;table width="233" cellpadding="0" cellspacing="0" border="0" style="width:175pt;border-collapse:collapse;"&gt;
&lt;colgroup&gt;&lt;col width="107" style="width:80pt;mso-width-source:userset;mso-width-alt:3913;"&gt;&lt;/col&gt;&lt;col width="126" style="width:95pt;mso-width-source:userset;mso-width-alt:4608;"&gt;&lt;/col&gt;&lt;/colgroup&gt;
&lt;tbody&gt;
&lt;tr style="height:16.5pt;"&gt;
&lt;td width="107" height="22" class="xl65" style="background-color:transparent;width:80pt;height:16.5pt;border:windowtext 1pt solid;"&gt;&lt;strong&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Port&lt;/span&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;td width="126" class="xl66" style="border-bottom:windowtext 1pt solid;border-left:#f0f0f0;background-color:transparent;width:95pt;border-top:windowtext 1pt solid;border-right:windowtext 1pt solid;"&gt;&lt;strong&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;Type of Traffic&lt;/span&gt;&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl71" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:#f0f0f0;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;UDP 53 DNS&lt;/span&gt;&lt;/td&gt;
&lt;td class="xl72" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:#f0f0f0;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;DNS&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl67" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;TCP 53 DNS&lt;/span&gt;&lt;/td&gt;
&lt;td class="xl68" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;DNS&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl67" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;TCP 135&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td class="xl68" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;RPC, EPM&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15pt;"&gt;
&lt;td height="20" class="xl67" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;TCP Static 53248&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td class="xl68" style="border-bottom:windowtext 0.5pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;FRsRpc&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:15.75pt;"&gt;
&lt;td height="21" class="xl69" style="border-bottom:windowtext 1pt solid;border-left:windowtext 1pt solid;background-color:transparent;height:15.75pt;border-top:windowtext;border-right:windowtext 0.5pt solid;"&gt;&lt;span style="font-size:small;"&gt;&lt;span style="font-family:Calibri;"&gt;TCP 389&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
&lt;td class="xl70" style="border-bottom:windowtext 1pt solid;border-left:windowtext;background-color:transparent;border-top:windowtext;border-right:windowtext 1pt solid;"&gt;&lt;span style="font-family:Calibri;font-size:small;"&gt;LDAP&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;br /&gt;Designing RODCs in the Perimeter Network&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/dd728028(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/dd728028(WS.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Restricting Active Directory replication traffic and client RPC traffic to a specific port&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/224196"&gt;http://support.microsoft.com/kb/224196&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Good discussion on RODC and firewall ports required:&lt;br /&gt;&lt;a href="http://forums.techarena.in/active-directory/1303925.htm"&gt;http://forums.techarena.in/active-directory/1303925.htm&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Further info on how RODC authentication works will help understand the ports:&lt;br /&gt;Understanding &amp;ldquo;Read Only Domain Controller&amp;rdquo; authentication &lt;br /&gt;&lt;a href="http://blogs.technet.com/b/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx"&gt;http://blogs.technet.com/b/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;&lt;br /&gt;References&lt;/h2&gt;
&lt;p&gt;How to configure a firewall for domains and trusts&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/179442"&gt;http://support.microsoft.com/kb/179442&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Active Directory and Active Directory Domain Services Port Requirements, Updated: June 18, 2009 (includes updated new ephemeral ports for Windows Vista/2008 and newer). This also discusses RODC port requirements. You must also make sure the ephemeral ports are opened. They are:&lt;br /&gt;&amp;nbsp;&amp;nbsp; TCP &amp;amp; UDP 1025-5000&lt;br /&gt;&amp;nbsp;&amp;nbsp; TCP &amp;amp; UDP 49152-65535&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/dd772723(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/dd772723(WS.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Windows 2008, 2008 R2, Vista and Windows 7 Ephermeral Port range has changed from the ports used by Windows 2003 Windows XP, and Windows 2000. Default ephemeral (Random service dynamic response ports) are UDP 1024 - 65535 (See KB179442 below), but for Vista and Windows 2008 it&amp;#39;s different. Their default start port range is UDP 49152 to UDP 65535 (see KB929851 below).&lt;/p&gt;
&lt;p&gt;Quoted from KB929851 (link posted below): &amp;quot;To comply with Internet Assigned Numbers Authority (IANA) recommendations, Microsoft has increased the dynamic client port range for outgoing connections in Windows Vista and in Windows Server 2008. The new default start port is 49152, and the default end port is 65535. This is a change from the configuration of earlier versions of Microsoft Windows that used a default port range of 1025 through 5000.&amp;quot; &lt;/p&gt;
&lt;p&gt;Windows Vista, Windows 7, Windows 2008 and Windows 2008 R2 Service Response Ports (ephemeral ports) have changed.&lt;br /&gt;&lt;a href="http://support.microsoft.com/?kbid=929851"&gt;http://support.microsoft.com/?kbid=929851&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Active Directory and Firewall Ports - I found it hard to find a definitive list on the internet for what ports needed opening for Active Directory to replication between Firewalls. ... &lt;br /&gt;&lt;a href="http://geekswithblogs.net/TSCustomiser/archive/2007/05/09/112357.aspx"&gt;http://geekswithblogs.net/TSCustomiser/archive/2007/05/09/112357.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Active Directory Replication over Firewalls, Jan 31, 2006. (includes older pre-Windows Vista/2008 ephemeral ports) &lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/bb727063.aspx"&gt;http://technet.microsoft.com/en-us/library/bb727063.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;How Domains and Forests Work&lt;br /&gt;Also shows a list of ports needed.&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc783351(v=ws.10).aspx"&gt;http://technet.microsoft.com/en-us/library/cc783351(v=ws.10).aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Paul Bergson&amp;#39;s Blog on AD Replication and Firewall Ports&lt;br /&gt;&lt;a href="http://www.pbbergs.com/windows/articles/FirewallReplication.html"&gt;http://www.pbbergs.com/windows/articles/FirewallReplication.html&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;&lt;br /&gt;Exchange DS Access ports&lt;/h2&gt;
&lt;p&gt;Configuring an Intranet Firewall for Exchange 2003, April 14, 2006. &lt;br /&gt;Protocol ports required for the intranet firewall and ports required for Active Directory and Kerberos communications &lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/bb125069.aspx"&gt;http://technet.microsoft.com/en-us/library/bb125069.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;Additonal Reading&lt;/h2&gt;
&lt;p&gt;Restricting Active Directory replication traffic and client RPC ...Restricting Active Directory replication traffic and client RPC traffic to a ... unique port, and you restart the Netlogon service on the domain controller. ...&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/224196"&gt;http://support.microsoft.com/kb/224196&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;How to restrict FRS replication traffic to a specific static port - How to restrict FRS replication traffic to a specific static port ... Windows 2000-based domain controllers and servers use FRS to replicate system policy ...&lt;br /&gt;&lt;a href="http://support.microsoft.com/kb/319553"&gt;http://support.microsoft.com/kb/319553&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Some firewalls may reject network traffic that originates from Windows Server 2003 Service Pack 1-based or Windows Vista-based computers&lt;br /&gt;This KB indicates Checkpoint firewalls having an issue with AD communications.&lt;br /&gt;&lt;a href="http://support.microsoft.com/?kbid=899148"&gt;http://support.microsoft.com/?kbid=899148&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;Checkpoint Firewall and AD, DNS and RPC Communications and Replication traffic&lt;/h2&gt;
&lt;p&gt;Checkpoint firewalls have a known issue if you are running version R55 or older. You will need to make a registry entry to allows traffic to flow between the 2 sites via the vpn. The preferred solution is to upgrade the Checkpoint firewall.&lt;/p&gt;
&lt;h3&gt;More info:&lt;/h3&gt;
&lt;p&gt;Some firewalls may reject network traffic that originates from Windows Server 2003 Service Pack 1-based or Windows Vista-based computers&lt;br /&gt;(This link relates to and helps resolve the Checkpoint issue)&lt;br /&gt;&lt;a href="http://support.microsoft.com/?kbid=899148"&gt;http://support.microsoft.com/?kbid=899148&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Note from one poster on the internet with a Checkpoint firewall:&lt;br /&gt;For Windows 2003 R2 and non-R2 remote domain controller we added the Server2003NegotiateDisable entry in &lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Rpc&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;I know you&amp;#39;ve enjoyed reading this. Well, whether you did or not, at least you now know what to do to make it work.&lt;/h3&gt;
&lt;p&gt;Comments, suggestions and corrections are welcomed!&lt;/p&gt;
&lt;h3&gt;Ace Fekay&lt;/h3&gt;</description></item></channel></rss>