CodeConnect.Net Beta


   Explore    Entry   Register  Login  
windowsxp-general
access
windows-vista-mail
windows-vista-general
windowsupdate
windowsmedia-player
access-forms
windows-live-mail-desktop
windowsxp-help_and_support
access-queries
access-modulesdaovba
access-formscoding
windows-server-sbs
windows-server-general
access-reports
windows-vista-music_pictures_video
windowsce-platbuilder
windows-live-messenger
windows-terminal_services
windows-powershell
windows-server-active_directory
access-gettingstarted
windows-mediacenter
windowsxp-hardware
windowsxp-network_web
windows-64bit-general
windows-live-sync
windows-vista-hardware_devices
windows-inetexplorer-ie6_outlookexpress
windows-group_policy
windows-server-networking
windows-vista-installation_setup
windows-vista-networking_sharing
windowsxp-basics
access-tablesdbdesign
windowsxp-perform_maintain
windows-vista-performance_maintenance
windows-networking-wireless
windows-vista-file_management
windows-inetexplorer-ie6-browser
windows-server-dns
windows-server-update_services
windows-vista-security
windows-vista-administration_accounts_passwords
windows-vista-games
windows-file_system
access-activexcontrol
windows-live-foldershare
windows-live-photogallery
access-developers-toolkitode
access-conversion




Can Reply:  Yes Members Can Edit: No Online: Yes
Zone: > Microsoft News > microsoft.public.windows.server.active_directory Tags:
Item Type: Date Entered: 11/30/2009 10:05:43 AM Date Modified: Subscribers: 0 Subscribe Alert
Rate It:
NR
XPoints: N/A Replies: 0 Views: 94 Favorited: 0 Favorite
8 Items, 1 Pages 1 |< << Go >> >|
Eric <Eric_m@no
NewsGroup User
Do I need to open port 137 and 138 from members server to the trusted PDC emulator ?11/30/2009 10:05:43 AM
Reply

0

Hello,

We have several trusted domain in our company. Some of them are still
using Windows NT domain.
Every domain is trusted with the same Active Directory domain.

The trusts relationship are working correctly but we have a problem
with a specific trusted domain.

Indeed, when we are connected to a server member of this specific NT
domain, we cannot display users of our AD trusted domain.
We have an error "Cannot display objects from this location because of
the following error : The specified domain either does not exist or
could not be contacted"

And then if we open port 137/UDP and 138/UDP from the specific server
member of NT and the PDC EMULATOR of our AD domain, then it working.

I dont understand why in this specific situation I need to open those
ports as they are not needed for my other trusted NT domain.

Moreover this means I have to open those ports for every member server
to our PDC emulator which is not very clean in term of security.

Do you have any idea of the problem here ?
Is it a bad WINS configuration ? A computer browser specific
configuration ?

Thank you !

--
Eric


Meinolf Weber [
NewsGroup User
Re: Do I need to open port 137 and 138 from members server to the trusted PDC emulator ?11/30/2009 10:08:30 AM
Reply

0

Hello Eric,

You need them.

See here for all needed ports in a trust:
http://support.microsoft.com/kb/179442/

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hello,
>
> We have several trusted domain in our company. Some of them are still
> using Windows NT domain.
> Every domain is trusted with the same Active Directory domain.
> The trusts relationship are working correctly but we have a problem
> with a specific trusted domain.
>
> Indeed, when we are connected to a server member of this specific NT
> domain, we cannot display users of our AD trusted domain.
> We have an error "Cannot display objects from this location because of
> the following error : The specified domain either does not exist or
> could not be contacted"
> And then if we open port 137/UDP and 138/UDP from the specific server
> member of NT and the PDC EMULATOR of our AD domain, then it working.
>
> I dont understand why in this specific situation I need to open those
> ports as they are not needed for my other trusted NT domain.
>
> Moreover this means I have to open those ports for every member server
> to our PDC emulator which is not very clean in term of security.
>
> Do you have any idea of the problem here ?
> Is it a bad WINS configuration ? A computer browser specific
> configuration ?
> Thank you !
>


"Ace Fekay [MCT
NewsGroup User
Re: Do I need to open port 137 and 138 from members server to the trusted PDC emulator ?11/30/2009 1:14:26 PM
Reply

0

"Eric" <Eric_m@nospam.hotmail.com> wrote in message
news:mn.f2997d9bbf75aaee.70874@nospam.hotmail.com...
> Hello,
>
> We have several trusted domain in our company. Some of them are still
> using Windows NT domain.
> Every domain is trusted with the same Active Directory domain.
>
> The trusts relationship are working correctly but we have a problem with a
> specific trusted domain.
>
> Indeed, when we are connected to a server member of this specific NT
> domain, we cannot display users of our AD trusted domain.
> We have an error "Cannot display objects from this location because of the
> following error : The specified domain either does not exist or could not
> be contacted"
>
> And then if we open port 137/UDP and 138/UDP from the specific server
> member of NT and the PDC EMULATOR of our AD domain, then it working.
>
> I dont understand why in this specific situation I need to open those
> ports as they are not needed for my other trusted NT domain.
>
> Moreover this means I have to open those ports for every member server to
> our PDC emulator which is not very clean in term of security.
>
> Do you have any idea of the problem here ?
> Is it a bad WINS configuration ? A computer browser specific configuration
> ?
>
> Thank you !
>
> --
> Eric
>
>


As Meinolf stated, that's an absolute requirement with NT4. NT4 is NetBIOS
based, unlike AD which is DNS based. Also, if your ports are that tightened
down, you may be blocking other necessary ports that are required for
communications.

--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Please reply back to the newsgroup or forum for collaboration benefit among
responding engineers, and to help others benefit from your resolution.

Ace Fekay, MCT, MCITP EA, MCTS Windows 2008 & Exchange 2007, MCSE & MCSA
2003/2000, MCSA Messaging 2003
Microsoft Certified Trainer

For urgent issues, please contact Microsoft PSS directly. Please check
http://support.microsoft.com for regional support phone numbers.


"Paul Bergson [
NewsGroup User
Re: Do I need to open port 137 and 138 from members server to the trusted PDC emulator ?11/30/2009 1:21:52 PM
Reply

0

Those are required as Meinolf pointed out. The NetBios piece is what is
biting you.

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4
Microsoft's Thrive IT Pro of the Month - June 2009

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.

"Eric" <Eric_m@nospam.hotmail.com> wrote in message
news:mn.f2997d9bbf75aaee.70874@nospam.hotmail.com...
> Hello,
>
> We have several trusted domain in our company. Some of them are still
> using Windows NT domain.
> Every domain is trusted with the same Active Directory domain.
>
> The trusts relationship are working correctly but we have a problem with a
> specific trusted domain.
>
> Indeed, when we are connected to a server member of this specific NT
> domain, we cannot display users of our AD trusted domain.
> We have an error "Cannot display objects from this location because of the
> following error : The specified domain either does not exist or could not
> be contacted"
>
> And then if we open port 137/UDP and 138/UDP from the specific server
> member of NT and the PDC EMULATOR of our AD domain, then it working.
>
> I dont understand why in this specific situation I need to open those
> ports as they are not needed for my other trusted NT domain.
>
> Moreover this means I have to open those ports for every member server to
> our PDC emulator which is not very clean in term of security.
>
> Do you have any idea of the problem here ?
> Is it a bad WINS configuration ? A computer browser specific configuration
> ?
>
> Thank you !
>
> --
> Eric
>
>


Eric <Eric_m@no
NewsGroup User
Re: Do I need to open port 137 and 138 from members server to the trusted PDC emulator ?11/30/2009 1:42:17 PM
Reply

0

Hi,

thank you for your answer.

Are you agree that these port requirements are needed for MEMBER
Servers ?

When I read the KB, I understand that these ports needs to be opened
between PDC and DC but not between MEMBER servers and the PDC Emulator
of the trusted domain.

Thank you

> Hello Eric,
>
> You need them.
>
> See here for all needed ports in a trust:
> http://support.microsoft.com/kb/179442/
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and confers
> no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>
>> Hello,
>>
>> We have several trusted domain in our company. Some of them are still
>> using Windows NT domain.
>> Every domain is trusted with the same Active Directory domain.
>> The trusts relationship are working correctly but we have a problem
>> with a specific trusted domain.
>>
>> Indeed, when we are connected to a server member of this specific NT
>> domain, we cannot display users of our AD trusted domain.
>> We have an error "Cannot display objects from this location because of
>> the following error : The specified domain either does not exist or
>> could not be contacted"
>> And then if we open port 137/UDP and 138/UDP from the specific server
>> member of NT and the PDC EMULATOR of our AD domain, then it working.
>>
>> I dont understand why in this specific situation I need to open those
>> ports as they are not needed for my other trusted NT domain.
>>
>> Moreover this means I have to open those ports for every member server
>> to our PDC emulator which is not very clean in term of security.
>>
>> Do you have any idea of the problem here ?
>> Is it a bad WINS configuration ? A computer browser specific
>> configuration ?
>> Thank you !
>>

--
Eric


"Ace Fekay [MCT
NewsGroup User
Re: Do I need to open port 137 and 138 from members server to the trusted PDC emulator ?11/30/2009 3:05:23 PM
Reply

0

"Eric" <Eric_m@nospam.hotmail.com> wrote in message
news:mn.f3727d9bfdb343a2.70874@nospam.hotmail.com...
> Hi,
>
> thank you for your answer.
>
> Are you agree that these port requirements are needed for MEMBER Servers ?
>
> When I read the KB, I understand that these ports needs to be opened
> between PDC and DC but not between MEMBER servers and the PDC Emulator of
> the trusted domain.
>
> Thank you
>
>> Hello Eric,

If any clients are to resolve and connect to the resources on the NT4
machine, they will need NetBIOS opened.

Ace




Eric <Eric_m@no
NewsGroup User
Re: Do I need to open port 137 and 138 from members server to the trusted PDC emulator ?11/30/2009 3:37:29 PM
Reply

0

Actually they dont need to connect to the ressources on the NT4
machine.

I am using a Windows 2003 server member of a PDC NT4 domain.
The PDC NT4 domain is trusted (bidirectionnal trust) with an Active
Directory domain.

I want to list my AD domain users from my Windows 2003 server member of
my NT4 domain.

Perhaps I am wrong but in the KB quoted above, it seems that I need to
open only port 138/UDP.

Am I wrong ?

Thank you

> "Eric" <Eric_m@nospam.hotmail.com> wrote in message
> news:mn.f3727d9bfdb343a2.70874@nospam.hotmail.com...
>> Hi,
>>
>> thank you for your answer.
>>
>> Are you agree that these port requirements are needed for MEMBER Servers ?
>>
>> When I read the KB, I understand that these ports needs to be opened
>> between PDC and DC but not between MEMBER servers and the PDC Emulator of
>> the trusted domain.
>>
>> Thank you
>>
>>> Hello Eric,
>
> If any clients are to resolve and connect to the resources on the NT4
> machine, they will need NetBIOS opened.
>
> Ace

--
Eric


"Ace Fekay [MCT
NewsGroup User
Re: Do I need to open port 137 and 138 from members server to the trusted PDC emulator ?11/30/2009 8:11:43 PM
Reply

0

"Eric" <Eric_m@nospam.hotmail.com> wrote in message
news:mn.f3e57d9b81d673c0.70874@nospam.hotmail.com...
> Actually they dont need to connect to the ressources on the NT4 machine.
>
> I am using a Windows 2003 server member of a PDC NT4 domain.
> The PDC NT4 domain is trusted (bidirectionnal trust) with an Active
> Directory domain.
>
> I want to list my AD domain users from my Windows 2003 server member of my
> NT4 domain.
>
> Perhaps I am wrong but in the KB quoted above, it seems that I need to
> open only port 138/UDP.
>
> Am I wrong ?
>
> Thank you
>
>> "Eric" <Eric_m@nospam.hotmail.com> wrote in message
>> news:mn.f3727d9bfdb343a2.70874@nospam.hotmail.com...
>>> Hi,
>>>
>>> thank you for your answer.
>>>
>>> Are you agree that these port requirements are needed for MEMBER Servers
>>> ?
>>>
>>> When I read the KB, I understand that these ports needs to be opened
>>> between PDC and DC but not between MEMBER servers and the PDC Emulator
>>> of the trusted domain.
>>>
>>> Thank you
>>>
>>>> Hello Eric,
>>
>> If any clients are to resolve and connect to the resources on the NT4
>> machine, they will need NetBIOS opened.
>>
>> Ace
>
> --
> Eric
>
>


You will also need 139 and all the UDP service response ports opened (also
known as emepheral ports: UDP 1024-5000 and if 2008 is involved, may as well
open the whole UDP range).

So what other ports have you not opened?

Also, can you elaborate on this sentence, please?
> I want to list my AD domain users from my Windows 2003 server member of my
> NT4 domain.

Where do you want to "list" the users on the NT4 side? In a resource (shared
permissions & security tab permissions or printer properties) or somewhere
else?

Ace



8 Items, 1 Pages 1 |< << Go >> >|







Similar:

list all aliases of a records!

reverse lookup issue

delete computer from forward lookup zone

dns scavenging not working properly

lots of event 4662 related to domaindnszones

unable to ping domain controller from adc

host resolve issue

dynamic dns not working

2 dns servers, 2 gateways, 3 subnets

win2008 active directory dns problems

sub-domain in active directory integrated zone

windows 7 doesnt update ptr

different url names for the same website

authorizing non domain computer to access dns?

dns resolution is very slow!

how do i disabled dns server caching on windows 2008 server?

outbound dns connection

site to site vpn and dns

need advise

bring dns in-house

dns setting in win2003 std server

client computer won't connect to domain - please help

dns forwarders best practices

prt records being removed

dhcp entries slow showing up in dns

2003 dns srv records - can you remove _sipinternaltls._tcp.

parent domain can't ping child domain

setting up dns on server 2008

hosts file problem

question on ms vpn client and dns resolution

dhcp register dns record

dns scavenge not removing stale dns records

windows administrator

the global query block list and event id 6268...

scripting ip change for an a record

dns query basics

help with an alias?

dns trust logon issues

modifying pdc entry in dns manually

dns static entries are overwritten by dhcp

dns server not populating zone file

possible to single point scavenging to entire forest

2 dns servers, 2 gateways, 3 subnets

dns.cache best practices

mx records for out of domain server

bad socket error stops email -- many dns connections

named.conf

resolve external web site w/o www

dns not transferring zones for no apparent reason

how to change secondary dc to primary dc?

   
  Privacy | Contact Us
All Times Are GMT