<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active Directory thru Pix in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/active-directory-thru-pix/m-p/713007#M977206</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't have a pointer to the MS KB article, but it's also possible to configure the servers to use a restricted port range for RPC (say, 5000 - 6000), and only open that range.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Jul 2007 12:23:27 GMT</pubDate>
    <dc:creator>lowen</dc:creator>
    <dc:date>2007-07-03T12:23:27Z</dc:date>
    <item>
      <title>Active Directory thru Pix</title>
      <link>https://community.cisco.com/t5/network-security/active-directory-thru-pix/m-p/713004#M977203</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 active directory forests that reside on either side of my PIX.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Forest A is on Inside interface&lt;/P&gt;&lt;P&gt;Forest B is on a DMZ interface security level 50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Microsoft guys would like to setup a trust between the 2 forests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to do this, RPC traffic, both port 135 and RPC dynamic ports (1024-65535) need to be allowed,  I don't however want to open those high ports unless I have to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Microsoft guy said that the firewall should be able to inspect RPC traffic in order to dynamically open higher ports when required by the application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't see a fixup for RPC on the Pix however.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Couldn't anyone shed some light on how I can make the Pix aware of the RPC traffic between the 2 AD forests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lee&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-directory-thru-pix/m-p/713004#M977203</guid>
      <dc:creator>lee.messenger</dc:creator>
      <dc:date>2019-03-11T10:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory thru Pix</title>
      <link>https://community.cisco.com/t5/network-security/active-directory-thru-pix/m-p/713005#M977204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;have your MS admins configure either a PPTP or IPSEC tunnel between the servers in one forest with the servers in the other forest.  This will minimize the number of ports you need to allow.&lt;/P&gt;&lt;P&gt;Have them search the MS KB for instructions on this - they're out there.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2007 17:37:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-directory-thru-pix/m-p/713005#M977204</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2007-07-02T17:37:59Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory thru Pix</title>
      <link>https://community.cisco.com/t5/network-security/active-directory-thru-pix/m-p/713006#M977205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Lee &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steven's solution is the best way to secure this traffic if you have to do this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The pix does have a fixup for RPC but it is for Sun RPC (ie Sun Microsystems who make a version of Unix called Solaris) and so this would not help you for AD anyway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2007 17:51:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-directory-thru-pix/m-p/713006#M977205</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-07-02T17:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory thru Pix</title>
      <link>https://community.cisco.com/t5/network-security/active-directory-thru-pix/m-p/713007#M977206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't have a pointer to the MS KB article, but it's also possible to configure the servers to use a restricted port range for RPC (say, 5000 - 6000), and only open that range.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jul 2007 12:23:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-directory-thru-pix/m-p/713007#M977206</guid>
      <dc:creator>lowen</dc:creator>
      <dc:date>2007-07-03T12:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory thru Pix</title>
      <link>https://community.cisco.com/t5/network-security/active-directory-thru-pix/m-p/713008#M977207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.microsoft.com/technet/prodtechnol/windows2000serv/technologies/activedirectory/deploy/confeat/adrepfir.mspx" target="_blank"&gt;http://www.microsoft.com/technet/prodtechnol/windows2000serv/technologies/activedirectory/deploy/confeat/adrepfir.mspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=c2ef3846-43f0-4caf-9767-a9166368434e&amp;amp;displaylang=en" target="_blank"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=c2ef3846-43f0-4caf-9767-a9166368434e&amp;amp;displaylang=en&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jul 2007 13:28:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-directory-thru-pix/m-p/713008#M977207</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2007-07-03T13:28:24Z</dc:date>
    </item>
  </channel>
</rss>

