Networking Forums

Networking Forums > Computer Networking > Windows Networking > Ports used by Windows server

Reply
Thread Tools Display Modes

Ports used by Windows server

 
 
Petri S
Guest
Posts: n/a

 
      09-24-2007, 06:18 AM
We have server that is partly isolated from domain network.
We have had problems with some gpo settings(proxy settings). Setting are
fine until computer is moved to that isolated network. After computer is
moved to that network it seem to lose proxy setting which are defined per
computer using Group policy loop back processing mode.

Network analysator shows that Domain Controllers tries to communicate with
that server through ports 3179 tcp, 3180 tcp, 3242 tcp and 3243 tcp should
we open those port? We have already opened port found from that list:
http://go.microsoft.com/fwlink/?linkid=21179

Kind regards,

Petri S

--
Petri S
 
Reply With Quote
 
 
 
 
Bill Grant
Guest
Posts: n/a

 
      09-24-2007, 06:51 AM
This all seems pretty pointless to me. What is the point of having a
firewall at all if you just keep opening more and more ports?

"Petri S" <(E-Mail Removed)> wrote in message
news:06F7C7B6-494E-43CD-84D0-(E-Mail Removed)...
> We have server that is partly isolated from domain network.
> We have had problems with some gpo settings(proxy settings). Setting are
> fine until computer is moved to that isolated network. After computer is
> moved to that network it seem to lose proxy setting which are defined per
> computer using Group policy loop back processing mode.
>
> Network analysator shows that Domain Controllers tries to communicate with
> that server through ports 3179 tcp, 3180 tcp, 3242 tcp and 3243 tcp
> should
> we open those port? We have already opened port found from that list:
> http://go.microsoft.com/fwlink/?linkid=21179
>
> Kind regards,
>
> Petri S
>
> --
> Petri S



 
Reply With Quote
 
Petri S
Guest
Posts: n/a

 
      09-24-2007, 07:06 AM
Point is to open only necessary ports between server and domain controllers
needed the server to function correctry. It is totally isolated from normal
workstations and servers.

--
Petri S


"Bill Grant" wrote:

> This all seems pretty pointless to me. What is the point of having a
> firewall at all if you just keep opening more and more ports?
>
> "Petri S" <(E-Mail Removed)> wrote in message
> news:06F7C7B6-494E-43CD-84D0-(E-Mail Removed)...
> > We have server that is partly isolated from domain network.
> > We have had problems with some gpo settings(proxy settings). Setting are
> > fine until computer is moved to that isolated network. After computer is
> > moved to that network it seem to lose proxy setting which are defined per
> > computer using Group policy loop back processing mode.
> >
> > Network analysator shows that Domain Controllers tries to communicate with
> > that server through ports 3179 tcp, 3180 tcp, 3242 tcp and 3243 tcp
> > should
> > we open those port? We have already opened port found from that list:
> > http://go.microsoft.com/fwlink/?linkid=21179
> >
> > Kind regards,
> >
> > Petri S
> >
> > --
> > Petri S

>
>
>

 
Reply With Quote
 
Steve Riley [MSFT]
Guest
Posts: n/a

 
      09-24-2007, 09:23 PM
Are you trying to protect that server from other computers in the network?
Will any other computers in the network need to connect with this server?
Give us an idea _why_ you've isolated this server.

--
Steve Riley
(E-Mail Removed)
http://blogs.technet.com/steriley
http://www.protectyourwindowsnetwork.com


"Petri S" <(E-Mail Removed)> wrote in message
news:FDB79128-B9B3-44A1-B4B9-(E-Mail Removed)...
> Point is to open only necessary ports between server and domain
> controllers
> needed the server to function correctry. It is totally isolated from
> normal
> workstations and servers.
>
> --
> Petri S
>
>
> "Bill Grant" wrote:
>
>> This all seems pretty pointless to me. What is the point of having a
>> firewall at all if you just keep opening more and more ports?
>>
>> "Petri S" <(E-Mail Removed)> wrote in message
>> news:06F7C7B6-494E-43CD-84D0-(E-Mail Removed)...
>> > We have server that is partly isolated from domain network.
>> > We have had problems with some gpo settings(proxy settings). Setting
>> > are
>> > fine until computer is moved to that isolated network. After computer
>> > is
>> > moved to that network it seem to lose proxy setting which are defined
>> > per
>> > computer using Group policy loop back processing mode.
>> >
>> > Network analysator shows that Domain Controllers tries to communicate
>> > with
>> > that server through ports 3179 tcp, 3180 tcp, 3242 tcp and 3243 tcp
>> > should
>> > we open those port? We have already opened port found from that list:
>> > http://go.microsoft.com/fwlink/?linkid=21179
>> >
>> > Kind regards,
>> >
>> > Petri S
>> >
>> > --
>> > Petri S

>>
>>
>>

 
Reply With Quote
 
Petri S
Guest
Posts: n/a

 
      09-25-2007, 05:16 AM
It is a Terminal Server which is available from internet(our users can use
some of our intranet services through internet on that specific Terminal
Server). We want to limit access from that server to only certain cervices,
fom example some Intranet pages(because of our Security Policy).

We found that it has some issue with applying proxy settings managed by GPO
when it is in that isolated network on normal network before isolating GPO
settings were applied normally. We have opened some ports to Domain
Controllers so that users are for example able to authenticate with Domain
credentials.

Network analysator shows that Domain Controllers tries to communicate with
that server through ports 3179 tcp, 3180 tcp, 3242 tcp and 3243 tcp should
we open those port, are those ports necessary for group policies or for some
other reason?

Kind regards,

Petri Siiskonen
--
Petri S


"Steve Riley [MSFT]" wrote:

> Are you trying to protect that server from other computers in the network?
> Will any other computers in the network need to connect with this server?
> Give us an idea _why_ you've isolated this server.
>
> --
> Steve Riley
> (E-Mail Removed)
> http://blogs.technet.com/steriley
> http://www.protectyourwindowsnetwork.com
>
>
> "Petri S" <(E-Mail Removed)> wrote in message
> news:FDB79128-B9B3-44A1-B4B9-(E-Mail Removed)...
> > Point is to open only necessary ports between server and domain
> > controllers
> > needed the server to function correctry. It is totally isolated from
> > normal
> > workstations and servers.
> >
> > --
> > Petri S
> >
> >
> > "Bill Grant" wrote:
> >
> >> This all seems pretty pointless to me. What is the point of having a
> >> firewall at all if you just keep opening more and more ports?
> >>
> >> "Petri S" <(E-Mail Removed)> wrote in message
> >> news:06F7C7B6-494E-43CD-84D0-(E-Mail Removed)...
> >> > We have server that is partly isolated from domain network.
> >> > We have had problems with some gpo settings(proxy settings). Setting
> >> > are
> >> > fine until computer is moved to that isolated network. After computer
> >> > is
> >> > moved to that network it seem to lose proxy setting which are defined
> >> > per
> >> > computer using Group policy loop back processing mode.
> >> >
> >> > Network analysator shows that Domain Controllers tries to communicate
> >> > with
> >> > that server through ports 3179 tcp, 3180 tcp, 3242 tcp and 3243 tcp
> >> > should
> >> > we open those port? We have already opened port found from that list:
> >> > http://go.microsoft.com/fwlink/?linkid=21179
> >> >
> >> > Kind regards,
> >> >
> >> > Petri S
> >> >
> >> > --
> >> > Petri S
> >>
> >>
> >>

>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
network ports on windows server 2003 Mohammad S Najdawi Windows Networking 2 08-22-2008 07:33 PM
Windows Homer Server and Providers blocking the required ports CadmannUK Broadband 2 12-18-2007 05:53 PM
Windows 2003 server only listening on local network ports? Bonge Boo! Windows Networking 3 09-01-2004 12:26 AM
Forwarding Ports on Windows 2003 Server Perquiaga Windows Networking 2 02-04-2004 07:53 PM
Enable\Disable ports in Windows 2000 server =?Utf-8?B?QW1pciBUYWw=?= Windows Networking 1 12-24-2003 03:35 AM



1 2 3 4 5 6 7 8 9 10 11