- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-19-2012 10:19 AM
I am trying to allow windows active directory services (2008 domain) through the firewall, in between zones. I have created my policy to allow the following applications:
active-directory
ms-ds-smb
msrpc
netbios-ss
dns
ms-win-dns
ms-wins
netbios-dg
ms-netlogon
I have created rules for bi-directional access.
I am unable to join a server to the domain however. I ran a packet capture and was seeing netbios traffic being dropped (UDP 137) but I have allowed several app-id applications that allow this protocol.
Any ideas?
Thanks!
10-19-2012 10:51 AM
Do you have any security profiles enabled? (I've noticed that joining a computer to the domain sets of the IPS/IDS if the profile is restrictive.)
Do you have any service/ports defined in the security policy? I've left mine to any because AD uses some many different ephemeral ports.
Edit: I checked my rule, and these are all the apps I have allowed for AD:
active-directory
dns
icmp
kerberos
ldap
ms-ds-smb
ms-netlogon
msrpc
netbios-dg
netbios-ss
ntp
ping
rpc
Message was edited by: Matthew Harding
10-19-2012 10:51 AM
Do you have any security profiles enabled? (I've noticed that joining a computer to the domain sets of the IPS/IDS if the profile is restrictive.)
Do you have any service/ports defined in the security policy? I've left mine to any because AD uses some many different ephemeral ports.
Edit: I checked my rule, and these are all the apps I have allowed for AD:
active-directory
dns
icmp
kerberos
ldap
ms-ds-smb
ms-netlogon
msrpc
netbios-dg
netbios-ss
ntp
ping
rpc
Message was edited by: Matthew Harding
10-19-2012 01:43 PM
Thanks! It looks like adding kerberos, rpc, and ldap seemed to do the trick.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!