NTDS and replication!

  • Thread starter Thread starter Jacob Lund
  • Start date Start date
J

Jacob Lund

Hi,



Due to firewall restrictions I have to be able to control how my domain
servers replicate with each other! I have 6 domain controllers and when I
look in "Active Directory Sites and Services" i can se how they replicate AD
information!



Now I setup how that should replicate, but for some reason the servers
automatically add new connections for replication - they are named
<automatically generated>. Now I get a lot of errors in my Event viewer
because these replications are denied connection by the firewall.



My question is - how do I avoid this automatically generation of replication
connections between the domain controllers?



Thanks,

Jacob
 
Surely a more elegant solution would be to create firewall
rules which permit the DCs to replicate across the
firewall.

e.g. allow all DCs inside the firewall to communicate with
all DCs outside the firewall using the required ports only
(53/88/135/137/138/389 etc) and mirrored pair statements.

I believe MS have published a paper which explains how
this may be done on the Windows 2000 web site. (I looked
but couldn't find :)

Neil
 
Back
Top