Access to the managed environment
If the environment managed by Active Roles is located behind a firewall, then the following ports must be open between the Active Roles Administration Service and managed environment.
For instance, if there is a firewall between Active Roles and DNS, then port 15172 must be open (Inbound/Outbound) on the Active Roles host (or the firewall between Active Roles and Exchange) and port 53 must be open on the DNS server (or the firewall between Active Roles and DNS).
Access to DNS servers
- Port 53 TCP/UDP Inbound/Outbound
Access to domain controllers
- Port 88 (Kerberos) TCP/UDP Inbound/Outbound
- Port 135 (RPC endpoint mapper) TCP Inbound/Outbound
- Port 139 (SMB/CIFS) TCP Inbound/Outbound
- Port 445 (SMB/CIFS) TCP Inbound/Outbound
- Port 389 (LDAP) TCP/UDP Outbound
- Port 3268 (Global Catalog LDAP) TCP Outbound
- Port 636 (LDAP SSL) TCP Outbound
This port is required if Active Roles is configured to access the domain by using SSL.
- Port 3269 (Global Catalog LDAP SSL) TCP Outbound
This port is required if Active Roles is configured to access the domain by using SSL.
- The TCP port allocated by RPC endpoint mapper for communication with the domain controller
You can configure Active Directory domain controllers to use specific port numbers for RPC communication. For instructions, see http://support.microsoft.com/kb/224196.
- The following ports must be open for the notifications specific to SaaS-based operations to work. The Web Interface machine should be able to resolve Service machine name for Notifications to work.
Access to Exchange servers
- Port 135 (RPC endpoint mapper) TCP Inbound/Outbound
- The TCP port allocated by RPC endpoint mapper for communication with the Exchange server.
You can configure Exchange servers to use specific port numbers for RPC communication. For more information, contact Microsoft Support.
The following ports must be open for operations related to the WinRM service to work:
-
Port 5985 (HTTP) TCP Inbound/Outbound
-
Port 5986 (HTTPS) TCP Inbound/Outbound
-
Port 80 TCP Inbound/Outbound