Domain Trust Open Ports
Bob from alpha domain is trying to log in to a workstation that s in omega domain.
Domain trust open ports. Then the workstation will contact a dc from alpha verify the user and login. Open the properties for the trust and click the authentication tab. Supporting services and tools. When creating trust relationships communications between the two domains is carried out over a number of protocols with each protocol using different tcp ip port.
You can change the scope of authentication after creating the trust. Read the windows server 2008 and later versions section of the microsoft support article how to configure a firewall for active directory domains and trusts to learn about the ports needed for a forest trust. The net logon service maintains a secured channel. Port here section or.
Or you can establish a trust through the point to point tunneling protocol pptp compulsory tunnel. This limits the number of ports that the firewall has to open. Trying to setup a domain trust between two different domains i came across microsoft s recommended ports that needed to be allowed which id fine. For a mixed mode domain that uses either windows nt domain controllers or legacy clients trust relationships between windows server 2003 based domain controllers and windows 2000 server based domain controllers may necessitate that all the ports for windows nt that are listed in the previous table be opened in addition to the following ports.
Here are some of the ports that you will need to open on both ends if you want to configure a domain trust across the firewall. That workstation will check with it s own dcs to get the relevant trust information. However this behavior may be changed by a specific registry setting. Bob is using his workstation in the alpha domain.
To support trusts and authentication some additional features and management tools are used. Port 135 tcp or udp for remote procedure call rpc service. Below is a list of ports which need to be enabled on the firewall for a trust relationship. A mixed mode domain with either nt domain controllers or legacy clients 2.
For example when a client computer needs to authenticate it connects to a server which hosts kdc service and which is listening on the port 88. The following ports need to be opened if you have once of the following.