Penn State Mark Windows Active Directory Service at Penn State banner Information Technology Services

 

How To: Install a Child Domain behind a firewall


Prerequisite:

You must have client machines and/or servers that are members of the ACCESS.PSU.EDU forest. You must also configure a software or hardware firewall.

Firewall Configuration:

Windows Active Directory

All UDP and TCP connections to/from our servers, provided below, should be allowed through a firewall, as they use dynamically-assigned port numbers and can use many ports at any given time.

Kerberos 5 Authentication Service

Please see the listing available on ITS' Information for Firewall Users page. This page is restricted to Penn State faculty/staff via WebAccess authentication.

DNS Communications

DNS communications must be open so that other DNS servers can find the correct SRV records; therefore, port 53 must be open to everyone.


The Pennsylvania State University ©2008. All rights reserved.
Alternative Media - Nondiscrimination Statement
This site maintained by Academic Services and Emerging Technologies, a unit of Information Technology Services.

Problem reports and requests for assistance should be directed to ITS Help Desk staff.

Last revised: Thursday, January 31, 2008.