Protocols, Ports, and Firewall Rules

Protocols, Ports, and Firewall Rules

  • Comments 7

TechReady4 (internal technical readiness field event in Seattle) went really well.  Some good times.  Wanted to share some data from a couple slides in the advanced deployment deck.  Refer to the TechNet Planning Security for additional details: Plan for secure communication within a server farm, Plan security hardening for server roles within a server farm (Office SharePoint Server).  You can also look forward to an extranet document and logical architectures document that will both help planning out your extranet/internet site better. 

All protocols are HTTP-based

Inbound/Outbound

From

Port

To

Inbound

Client IPs (as applicable)

TCP 80 or 443

ISA Web Pub or

WFE

Inbound

TS Jump point

RDP (TCP 3389)

For Remote Admin

APP (Central Admin /SSP Admin)

Inbound

All SharePoint Server (Depends on Central Admin config)

Office Server Web Services, TCP 56737, SSL 56738

App (Central Admin /SSP Admin)

Inbound

Index

***

TCP 80 or 443

WFE

Outbound

ALL SharePoint Svrs

(Based on Auth)

DS (TCP 445)

RPC (TCP 135)

DNS (UDP 53)

Kerberos (UDP 88)

LDAP/S (UDP 389/636)

DC/DNS (LDAP)

Outbound/(Inbound if applicable)

WFE (alerts or mail enabled list)

SMTP (TCP 25)

SMTP/Exchange

Outbound

ALL SharePoint Svrs

SQL (TCP 1433) or SSL custom port

SQL

Outbound

WFE (Search Request)

Search Query, either NBT (TCP/UDP 137, 138,139) or Direct-hosted SMB (TCP/UDP 445)

Query

Outbound

Index (Propagation)

Search Query, either NBT (TCP/UDP 137, 138,139) or Direct-hosted SMB (TCP/UDP 445)

Query

Outbound

WFE (SSO)

RPC for SSO – (TCP 135), plus random high ports (Dynamic RPC) or restricted high ports (Static RPC)

APP Servers

 

* Don't forget outbound RSS/XML displays, and any online web parts 

** Don't forget outbound to BDC connections and datasources as applicable

*** Don't Forget outbound ports (80/25, etc...) to crawl seeds, content sources

Warning: As with anything be sure to consider what is necessary, don't just do it to make it work.

Leave a Comment
  • Please add 8 and 8 and type the answer here:
  • Post
  • PingBack from http://www.do-ict.nl/2007/02/14/protocols-ports-and-firewall-rules-for-sharepoint/

  • In researching how to deploy MOSS into a customer's data centre, I needed to find out exactly what and

  • Hace unos días instalé un firewall personal llamdo GhostWall en mi laptop (cpu Turion 64-bit). No hay

  • Joel Oleson has posted an article decribing the protocols, ports and firewall rules with regards to MOSS

  • Hi ... i was just looking and couldnt really find any information. I was wondering if you knew if Usage Analysis needs any special ports need to be opened for this work.

  • We have a moss farm, but cannot open port 445 and due to this search is not working, is there any other way to make the search work using other ports

    ?

  • excellent article that is completely useful but are some of the ports uncustomizable

Page 1 of 1 (7 items)