How Can I Restrict Active Directory Replication Traffic to a Specific Port?

By default, Active Directory (AD) replication via remote procedure calls (RPCs) takes place dynamically over an available port via the RPC Endpoint Mapper using port 135 (the same port as Microsoft Exchange).

ITPro Today

September 21, 2000

1 Min Read
ITPro Today logo in a gray background | ITPro Today

By default, Active Directory (AD) replication via remote procedure calls (RPCs) takes place dynamically over an available port via the RPC Endpoint Mapper using port 135 (the same port as Microsoft Exchange). An administrator can override this functionality and specify the port that all replication traffic passes through. To set a specific port, perform the following steps:

1. Start a Registry Editor (e.g., regedit.exe)
2. Navigate to HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesNTDSParameters.
3. From the Edit menu, select New, then DWORD Value.
4. Enter the name as "TCP/IP Port" without the quotes and click Enter.
5. Double-click TCP/IP Port, set the value to the desired port, and click OK.
6. Close the Registry Editor and reboot.

Because some routers filter packets, administrators must be sure that they don't filter out any intermediate network devices or software that filters packets between domain controllers.

http://www.windows2000faq.com/Articles/Index.cfm?ArticleID=15569

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like