Windows Server 2003 Security Infrastructures: Core Security Features (HP Technologies)

Many enterprise environments require Windows trust relationships to be set up between domains or forests that are crossing firewalls. Because in Windows 2000 and later the true security boundary is the forest, this has become a common practice between different Windows forests: Some organizations, for example, maintain separate internal and external Windows forests that are separated by a firewall. Table 3.5 gives an overview of common multiforest enterprise scenarios and their trust-related firewall requirements, both for inbound and outbound traffic.

Table 3.5: Firewall Port Configuration for Multiforest Scenarios

Scenario

Inbound Ports

Outbound Ports

Trust setup on both sides from an internal forest (two-way trust)

LDAP

389 UDP and TCP

MS DS

445 TCP

Kerberos

88 UDP

Trust validation from an internal forest domain controller to an external forest domain controller (outgoing trust only)

LDAP

389 UDP and TCP

MS DS

445 TCP

DCE endpoint resolution—portmapper

135 TCP

Netlogon

fixed port

Using object picker on an external forest to add objects in an internal forest to groups and ACLs

LDAP

389 UDP and TCP

LSA

fixed port

Netlogon

fixed port

Kerberos

88 UDP

DCE endpoint resolution—portmapper

135 TCP

Set up a trust on the external forest from the external forest

LDAP

389 UDP and TCP

MS DS

445 TCP

Kerberos

88 UDP

Network logon feature from an internal forest domain controller to an external forest domain controller with Kerberos authentication

MS DS

445 TCP

Kerberos

88 UDP

Network logon feature from an internal forest domain controller to an external forest domain controller with NTLM authentication

DCE Endpoint resolution—portmapper

135 TCP

Netlogon

fixed port

Windows trust setup and maintenance heavily rely upon RPCs. One of the key problems with RPCs in a firewall environment is its use of dynamic port allocations (see the previous side note). In order to limit the amount of firewall ports that must be opened to enable trust-related RPC traffic to pass through the firewall, Windows Server 2003 includes the following registry keys:

Категории