cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3140
Views
0
Helpful
2
Replies

Active Directory Behind ASA Firewalls & RPC Traffic

avilt
Level 3
Level 3

As per the following MS article, we need to allow TCP/UDP dynamic ports 49152 through 65535 for the Windows 2008 R2 active directory to work if the clients/domain controllers are behind the firewall.

http://technet.microsoft.com/en-us/library/dd772723(WS.10).aspx

 

Can we minimize this ports by using the ASA application inspection features?

 

 

2 Replies 2

Vibhor Amrodia
Cisco Employee
Cisco Employee

Hi,

You can use DCERPC inspection on the ASA device.

Check these URL links and i think they should help you with your query:-

https://supportforums.cisco.com/document/67706/dcerpc-inspection-asapixfwsm

http://www.experts-exchange.com/Security/Software_Firewalls/Cisco_PIX_Firewall/Q_28128906.html

Thanks and Regards,

Vibhor Amrodia

I am unable to view expertexchange. With DCE/RPC inspection on ASA, can I do away with dynamic port range?

Review Cisco Networking products for a $25 gift card