How do I change domain password over dial up without port 445?

  • Thread starter Thread starter NMinchin
  • Start date Start date
N

NMinchin

Hi,

Would anyone be able to tell me which ports need to be opened on a
firewall to allow laptop users to change their passwords across VPN?

The laptops use CheckPoint SecureClient on WinXP dial up to the
Internet and the DC is Windows 2000 Server on a dedicated leased line.

I have successfully achieved the desired results by opening TCP port
445 but this is too much I think as this also allows file shares to be
accessed and all sorts of viruses and DoS stuff to enter.

I think the solution has something to do with Kerberos port 88 and
some others but I don't know exactly which ones?

TIA.

NMinchin
 
depending on what do you use for VPN, you need to enable the PPTP ports or
the L2TP ports or both

for PPTP VPN uses TCP Port 1723, IP Protocol 47 (GRE)
for L2TP: UDP Port 1701;
for IPSec: Pass protocol 50 and 51.
 
Back
Top