<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic replication Active Directory, ports issues in firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/replication-active-directory-ports-issues-in-firewall/m-p/1983724#M409873</link>
    <description>&lt;DIV&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i am facing some issue&amp;nbsp; in active directory replication between my Active Directory User&amp;nbsp; Database located in two different locations. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I&amp;nbsp; am not doing any Port based ACL in the firewall, and there is no static&amp;nbsp; / dynamic NAT-ng used between the server ip ranges (nat 0).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) what could be the possible issue in this?&lt;/P&gt;2) do i need to issue any command in the FWSM Module to make use / open the dynamic ports ?&lt;P&gt;3) How can i make sure that these ports are not opend or not blocked on the firewall.&lt;/P&gt;&lt;BR /&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;below are some of the ports used for this, based on the information from Microsoft Team. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tcp 5389&lt;/P&gt;&lt;P&gt;tcp 5722&lt;/P&gt;&lt;P&gt;tcp 5729&lt;/P&gt;&lt;P&gt;tcp3268&lt;/P&gt;&lt;P&gt;tcp 3269&lt;/P&gt;&lt;P&gt;tcp 445&lt;/P&gt;&lt;P&gt;udp 445&lt;/P&gt;&lt;P&gt;udp 88&lt;/P&gt;&lt;P&gt;udp 2535&lt;/P&gt;&lt;P&gt;udp 389&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tcp 1025 - 5000&lt;/P&gt;&lt;P&gt;tcp 44152 - 65535&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate your valuable support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Sunny&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Mon, 11 Mar 2019 23:38:08 GMT</pubDate>
    <dc:creator>Jacob Samuel</dc:creator>
    <dc:date>2019-03-11T23:38:08Z</dc:date>
    <item>
      <title>replication Active Directory, ports issues in firewall</title>
      <link>https://community.cisco.com/t5/network-security/replication-active-directory-ports-issues-in-firewall/m-p/1983724#M409873</link>
      <description>&lt;DIV&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i am facing some issue&amp;nbsp; in active directory replication between my Active Directory User&amp;nbsp; Database located in two different locations. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I&amp;nbsp; am not doing any Port based ACL in the firewall, and there is no static&amp;nbsp; / dynamic NAT-ng used between the server ip ranges (nat 0).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) what could be the possible issue in this?&lt;/P&gt;2) do i need to issue any command in the FWSM Module to make use / open the dynamic ports ?&lt;P&gt;3) How can i make sure that these ports are not opend or not blocked on the firewall.&lt;/P&gt;&lt;BR /&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;below are some of the ports used for this, based on the information from Microsoft Team. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tcp 5389&lt;/P&gt;&lt;P&gt;tcp 5722&lt;/P&gt;&lt;P&gt;tcp 5729&lt;/P&gt;&lt;P&gt;tcp3268&lt;/P&gt;&lt;P&gt;tcp 3269&lt;/P&gt;&lt;P&gt;tcp 445&lt;/P&gt;&lt;P&gt;udp 445&lt;/P&gt;&lt;P&gt;udp 88&lt;/P&gt;&lt;P&gt;udp 2535&lt;/P&gt;&lt;P&gt;udp 389&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tcp 1025 - 5000&lt;/P&gt;&lt;P&gt;tcp 44152 - 65535&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate your valuable support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Sunny&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:38:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replication-active-directory-ports-issues-in-firewall/m-p/1983724#M409873</guid>
      <dc:creator>Jacob Samuel</dc:creator>
      <dc:date>2019-03-11T23:38:08Z</dc:date>
    </item>
    <item>
      <title>replication Active Directory, ports issues in firewall</title>
      <link>https://community.cisco.com/t5/network-security/replication-active-directory-ports-issues-in-firewall/m-p/1983725#M409874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="text-align: justify;"&gt;Hi Bro&lt;/P&gt;&lt;P style="text-align: justify;"&gt;If you’re not doing any port based ACL in your FWSM, I can only assume you’re permitting the rules between both the AD by IP e.g. access-list inside permit ip host 1.1.1.1 host 2.2.2.2, am I right? I hope you can PING between both the AD, otherwise this could be a routing issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;Listed below are some commands that you could type to investigate this issue further;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;a)&amp;nbsp;&amp;nbsp; show np block (hardware buffer counters) - if they are non-zero and increasing it's bad. You're most likely running into hardware limitation of the FWSM. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;b)&amp;nbsp;&amp;nbsp; show np all stats | i RTL and show np all stats | i RL will show you if the packets are dropped because of software rate limiting mechanisms built into network processors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;Perhaps, what you need is to enable the “xlate-bypass” command. By default, the FWSM creates NAT sessions for all connections even if you do not use NAT. You can disable NAT sessions for untranslated network traffic, which is called xlate bypass, in order to avoid the maximum NAT session limit. The xlate-bypass command can be configured as shown:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;hostname(config)#xlate-bypass&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;If the xlate-bypass doesn’t resolve your issue, please do ensure you’ve a static NAT or dedicated nat/global in place.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;The last resort is to enable sysoption np completion-unit, this magic option is invoking special processing created to address scenarios in which FWSM was known to introduce out of order packets for TCP streams.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2012 04:07:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replication-active-directory-ports-issues-in-firewall/m-p/1983725#M409874</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-08-17T04:07:33Z</dc:date>
    </item>
    <item>
      <title>replication Active Directory, ports issues in firewall</title>
      <link>https://community.cisco.com/t5/network-security/replication-active-directory-ports-issues-in-firewall/m-p/1983726#M409875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Ram,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp; a lot for the update.&amp;nbsp; thanks again for pointing me towards the hardware limitations issues, because i too believe it is not related to somiething of ports, caz most of the replication part is working fine, like if we have 100 users, the replication happends for 90 / 95 users, but remaining its not. So could be some issue related to the hardware limitation / NAT size limitation also. But same time some other replications are also happenign beside the AD, like file replication on certain applications, and it works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to track what happening at the time of replication? How we can do that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont have any log server and it is risky if i need to run a debug, caz the firewall sits in a highly critical production network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards&lt;/P&gt;&lt;P&gt;Jacob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Aug 2012 07:20:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replication-active-directory-ports-issues-in-firewall/m-p/1983726#M409875</guid>
      <dc:creator>Jacob Samuel</dc:creator>
      <dc:date>2012-08-25T07:20:16Z</dc:date>
    </item>
    <item>
      <title>replication Active Directory, ports issues in firewall</title>
      <link>https://community.cisco.com/t5/network-security/replication-active-directory-ports-issues-in-firewall/m-p/1983727#M409876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro &lt;/P&gt;&lt;P&gt;I guess the best way to find this root cause is to place a packet sniffer e.g. Wireshark / Ethereal, anywhere along the path between both the WIndows AD. This will tell you what's actually happening.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Aug 2012 06:37:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replication-active-directory-ports-issues-in-firewall/m-p/1983727#M409876</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-08-26T06:37:48Z</dc:date>
    </item>
  </channel>
</rss>

