Enabling Windows Firewall On Domain Controllers

| | No TrackBacks
Firewall is an important tool of creating acceptable level of security. Under normal circumstances, it must be turned on with 'whitelist' approach (everything not allowed explicitly is blocked). However, one should be careful when enabling firewall on domain controllers, since they can be efficiently rendered broken if firewall is improperly configured (e.g. preventing workstations from connecting).

Below are instructions on what should be done to enable firewall on a domain controller.

Enable the Fire And Print exception in firewall settings.

Add program exceptions for lsass.exe and ntfrs.exe locate usually in %WINDIR%\SYSTEM32

Allow the following port exceptions: 53 (TCP and UDP), 88 (TCP and UDP), 123 (UDP), 135 (TCP), 137 (TCP), 389 (UDP), 464 (TCP and UDP) and 636 (TCP).

The above is the minimal exception set to allow normal domain controller functioning.

No TrackBacks

TrackBack URL: /blog/mt-tb.cgi/30

blog comments powered by Disqus

About this Entry

This page contains a single entry by Konstantin Boyandin published on December 11, 2009 1:19 PM.

Port 445 And Trust Creation was the previous entry in this blog.

Server Based Printers And Security Issues is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.