Procedure and the consequence when enabling the built-in firewall profiles for Domain Controllers?

EnterpriseArchitect 5,036 Reputation points
2024-03-15T13:16:36.9866667+00:00

I need help understanding how to manually set the Windows Firewall for all Domain Controllers with Advanced Security capabilities by enabling the Active Directory Domain Services and Active Directory Web Services rule groups.

Screenshot 2024-03-16 000221

User's image

According to this official article from Microsoft: Service overview and network port requirements - Windows Server | Microsoft Learn

There are Port 49152-65535 – RPC Ephemeral Ports how do I ensure these ports are not blocked by the Windows Firewall?

Any assistance and clarity would be highly appreciated.

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,569 questions
Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,425 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,525 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,154 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,775 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Thameur-BOURBITA 32,621 Reputation points
    2024-03-15T14:52:00.8+00:00

    Hi @EnterpriseArchitect

    When you enable windows firewall , you should be sure that all ports required for domain controller are opened, for more information you can refer to the following link :

    How to configure a firewall for Active Directory domains and trusts


    Please don't forget to accept helpful answer


  2. Daisy Zhou 20,791 Reputation points Microsoft Vendor
    2024-03-18T05:54:48.51+00:00

    Hello EnterpriseArchitect,

    Thank you for posting in Q&A forum.

    You can check if these ports are blocked or not by the Windows Firewall based on the way in the following link.
    https://www.itechtics.com/check-windows-firewall-blocking-ports/

    Also, here is a similar thread with method for your reference.

    https://serverfault.com/questions/26564/how-to-check-if-a-port-is-blocked-on-a-windows-machine

    I hope the information above is helpful.

    If you have any questions or concerns, please feel free to let us know.

    Best Regards,

    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.