Domain Controller Replication Ports
Modify registry to select a static port.
Domain controller replication ports. Windows server 2008 newer versions of windows server have increased the dynamic client port range for outgoing connections. There might be some rpc ports that you need to open in addition and that question is probably best answered by your microsoft technical account manager. These ports relate to active directory and you should only need to open them if you do not have a global catalog gc or domain controller dc in your dmz. Replicating traffic between domain controllers.
Tcp port 139 and udp 138 for file replication service between domain controllers. This is to used to set the specific ad replication port. Restricting active directory rpc traffic to a specific port. Udp port 389 ldap to handle normal queries from client computers to the domain controllers.
The new default start port is 49152 and the default end port is 65535. Frequently you must also manually set the file replication service frs rpc port because ad and frs replication replicate with the same domain controllers. Tcp and udp port 53 dns from client to domain controller and domain controller to domain controller. Tcp port 139 and udp 138 file replication service between domain controllers.
Both udp and tcp port 135 are required for communication between domain controllers and clients to domain controllers. Udp port 389 for ldap to handle normal queries from client computers to the domain controllers. Udp port 389 for ldap network port is used to handle normal authentication queries from client computers. Simple mail transfer protocol smtp can be used in certain situations schema configuration and global catalog replication but not domain naming context limiting its usefulness.
Udp and tcp port 135 for domain controllers to domain controller and client to domain controller operations. Tcp and udp port 464 kerberos password change. By default it uses dynamic port to replicate data from dc in one site to another. The domain controllers and active directory section in service overview and network port requirements for windows.
Tcp and udp port 445 file replication service. Tcp and udp port 445 for file replication service. Active directory relies on remote procedure call rpc for replication between domain controllers. Therefore you must increase the rpc port range in your firewalls.
The frs rpc port should use a different port. Do not assume that clients only use the netlogon rpc services and thus only the setting dctcpipport is required. This is applicable for restriction ad replication to a specific port range. This change was.
Fixed port for sysvol replication to tcp 51000 dfsrdiag staticrpc port 51000 restart ad domain controller for the changes to take affected and change the firewall rule to allow only tcp 50 000 51 000 as below verification that fixed ports are working.