Domain Controller Firewall Ports
This change was made to comply with internet assigned numbers authority iana recommendations.
Domain controller firewall ports. These ports are required by both client computers and domain controllers. Tcp 464 and udp 464 for joining and regularly changing passwords. In general there are more cons than pros at the top of the list and more pros than cons at the bottom.
Block access from 10 10 10 0 24 to 172 16 1 0 24. Tcp and udp port 464 kerberos password change. Active directory using several ports to communication between domain controllers to clients.
Each approach has its pros and cons. Firewall policy in pfsense. Securing domain controllers against attack.
Tcp and udp port 53 dns from client to domain controller and domain controller to domain controller. Tcp and udp port 445 file replication service. Windows 2019 ad domain controller 10 10 10 200.
Encapsulate domain controller dc to dc traffic inside the ip security protocol ipsec and open the firewall for that. Tcp port 139 and udp 138 file replication service between domain controllers. Windows server 2016 windows server 2012 r2 windows server 2012.
At a minimum they must listen on these required ports. The new default start port is 49152 and the default end port is 65535. So although this document describes how to do all three most.