Firewall Ports Required To Join AD Domain - AventisTech
Maybe your like
Refer to the lab below on the testing done to verify Firewall Ports Required to Join AD Domain
Components in this lab
- Windows 10 Machine – 172.16.1.200
- Windows 2019 AD Domain Controller – 10.10.10.200
- Firewall Policy in PfSense
- Block Access from 172.16.1.0/24 to 10.10.10.0/24
- Block Access from 10.10.10.0/24 to 172.16.1.0/24
The Firewall Ports will be opened one by one from 172.16.1.0/24 to 10.10.10.0/24 to verify the actual ports required
Firewall Ports required to join AD Domain (Minimum)
Windows 10 Client can join to Windows 2019 AD Domain with the following Ports allow in Firewall
Without TCP High Ports open
The following Message appear even join to domain successfully and there is a lot of TCP high ports are blocked in Firewall
- Group Policy cannot be applied
- It take very long time to for computer to startup and login to domain successfully


Optional Ports
Without TCP 464 Open
User can still change their password successfully even thought TCP 464 is blocked in Firewall
Firewall Rules in pfesense Firewall
The following Firewall Rule is created
- Traffics from WIN10 (172.16.1.200) to AD Domain Controller (10.10.10.200)

- Traffics from AD Domain Controller (10.10.10.200) to WIN10 (172.16.1.200) – All Block

Reference Links
https://support.microsoft.com/en-us/kb/832017
Related
Post navigation ← Previous PostNext Post →Leave a Comment Cancel Reply
Your email address will not be published. Required fields are marked *
Type here..Name*
Email*
Website
Save my name, email, and website in this browser for the next time I comment.
SearchSearchRecent Posts
- How to Configure Postfix Email Relay via Office 365
- IPSec IKEv2 VPN between FortiGate and Cisco ASA
- IPSec VPN between FortiGate and Cisco ASA
- Authenticate Aruba Devices Against ClearPass with RADIUS
- Authenticate ClearPass Admin Against AD
Tag » Active Directory Ports Windows Server 2016
-
Configure Firewall For AD Domain And Trusts - Windows Server
-
Service Overview And Network Port Requirements - Windows Server
-
Windows Server 2016-active Directory Domain Services Port Rollup
-
Complete List Of Active Directory Ports And What They Do Explained
-
Active Directory Ports: Service And Network Port Requirements For ...
-
How To Config Server 2016 Firewall Ports For Active Dir?
-
Protocols And Ports Required For Monitoring Active Directory ...
-
Windows Server 2016-Active Directory Domain Services Port ...
-
Active Directory Port List - MSNOOB
-
Active Directory Ports - Blog | Hamid Sadeghpour Saleh
-
Restricting Active Directory Communication Ports - Terminalworks Blog
-
Firewall For Windows Server 2016: Overview & Settings
-
Configuring Port Forwarding In Windows | Windows OS Hub
-
Change The Default Port For The Active Directory Server