2008 Server Enterprise RPC Dynamic Ports


i have new 2008 domain 2 domain controllers. trying join 2003 r2 enterprise server , 2008 enterprise server domain through firewall.

i have allowed tcp ports 53, 88, 135, 139, 326, 389, 445, 636, 3269

i have allowed udp ports 53, 88, 123, 137,138, 389, 445

 

i ran in trouble , error messages when attempting join domain. turns out that there bunch of dynamic rpc ports need allowed , analyzing firewall traffic, have identified tcp dynamic rpc ports server using. have temporarily allowed 20 ports in sequence windows using them , able join domain successfully.

 

the dynamic rpc ports windows uses initially begin @ random port, seem increment sequentially once start. i configure windows use rpc ports. found following 2 microsoft kb articles http://support.microsoft.com/kb/908472 and http://support.microsoft.com/kb/154596 . suggest use rpccfg.exe tool relocate , reduce rpc dynamic port range.

 

my problem/question know how many dynamic rpc ports should open on firewall. keep ports open absolute minimum. have read suggest opening 100 ports minimum. sound excessive me , allow no more 20 ports open on firewall dynamic rpc, 10 ports or less ideal.

 

additionally, know use rpccfg.exe. on host servers only, or on domain controllers well? need use rpccfg.exe on of servers attempting join domain? how rpc dynamic ports used? happen if allow dynamic rpc ports through firewall, not use rpccfg tool; increment out of allowable range , fail? there way configure dynamic rpc ports throught script?

 

all of instructions have found 2003 server , not sure if same instructions apply 2008 server.

 

this simple domain 7 domain members including 2 domain controllers. planning join possibly 10 more domain members on next year or two. there no plans exchange, understand use many dynamic rpc ports.

 

any suggestions or 2008 specific instructions (preferably microsoft technet or kb article) would appreciated.

 

thank you,

 

fabian

hello,

 

please note default dynamic port range tcp/ip has changed in windows vista , in windows server 2008. range 49152 65535, may change dynamic rpc ports start @ number larger 49152 instead of 5000. see following article more details:

 

the default dynamic port range tcp/ip has changed in windows vista , in windows server 2008:

http://support.microsoft.com/kb/929851

 

regarding first question, well, according previous article, minimum range of ports can set 255. if install additional applications use dynamic rpc, may need increase range.

 

regarding second question, may need run rpccfg.exe on computers, including dcs , member servers. general information ports used in active directory domain, suggest read following articles in detail, give answers last questions:

 

how configure firewall domains , trusts:

http://support.microsoft.com/default.aspx?scid=kb;en-us;q179442

 

service overview , network port requirements windows server system:

http://support.microsoft.com/kb/832017

 

for more information active directory , firewall configuration, view "active directory in networks segmented firewalls" microsoft white paper. this, visit following web site:

 

http://www.microsoft.com/downloads/details.aspx?familyid=c2ef3846-43f0-4caf-9767-a9166368434e&displaylang=en

 

i hope helps. luck.

 

best regards,

chang yin



Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2