cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
491
Views
0
Helpful
2
Replies

ASA: what are the TCP ports to be permitted for microsoft AD/Exchange/IIS?

danny2125
Level 1
Level 1

Dear all,

I need to configure a access rule in ASA 5550 to permit microsoft AD/Exchange/IIS services, anyone has the idea what TCP/UDP ports to be opened?

Like other firewall they have predifined services object for these MS services, so is there any other way to configure the ASA to permit such services, for instance, use predefined objects if it has...

Thanks

DYBC2125

2 Replies 2

Marcin Latosiewicz
Cisco Employee
Cisco Employee

Most of this information can be found on microsoft's excellent knowledgebase pages (IF not part of well known services -> check /etc/services on most unix systes)

If in doubt, best to see what ASA is blocking, enable logging to buffer on informational level:

-------

logging time

logging buffer-size 1040000

logging buffere info

-------

Following this you can do:

-------

show logg | i Deny

-------

or

------

show logg | i $IP.ADD.RE.SS

-------

To see what is being denied :]

Review Cisco Networking products for a $25 gift card