Computing.Net > Forums > Windows 2000 > block domain access via firewall

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

block domain access via firewall

Reply to Message Icon

Name: carl parker
Date: May 11, 2005 at 09:14:28 Pacific
OS: 2000/2003
CPU/Ram: 2ghz/1gb
Comment:

I want to know if there is a way I can join a domain and then effectively block all access from the domain to my pc via firewall. I know that I also need to remove the domain accounts from my local machine but what ports do I need to block as well?

Thank you,

Leto the Just.



Sponsored Link
Ads by Google

Response Number 1
Name: jimminy
Date: May 11, 2005 at 10:31:41 Pacific
Reply:

Good firewall policy is to block everything by default. Then, allow traffic only on necessary ports. This should effectively block domain traffic.

If you want to selectively block only the ports used by Active Directory - which you shouldn't, becuase it is bad firewall policy - block ports 88 445 and 135. This should break your ability to authenticate to the domain. Depending on what you mean by "all access" you may need to block other ports as well. But you will have already done that becuase you are implememting good firewall policies. Right?


0

Response Number 2
Name: ooglenz1
Date: May 13, 2005 at 07:58:10 Pacific
Reply:

how can remove domain accounts locally?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

there are domain accounts so NOT local accounts


0

Response Number 3
Name: jimminy
Date: May 13, 2005 at 08:01:19 Pacific
Reply:

Maybe he meant local profiles?


0

Response Number 4
Name: Jennifer SUMN
Date: May 13, 2005 at 12:15:21 Pacific
Reply:

ooglenze, you may want to post this separate issue in it's own thread, and be a little more specific, as Domain Accounts are created on a DC, and local accounts are created on a client/node/machine. Are you talking about removing User Accounts from a DC?


0

Response Number 5
Name: carl parker
Date: May 17, 2005 at 08:18:04 Pacific
Reply:

I just want to physically join the domain but block the ports that allow AD and domain admins access to manage my PC.


0

Related Posts

See More



Response Number 6
Name: jimminy
Date: May 17, 2005 at 09:19:54 Pacific
Reply:

What do you mean by "physically join the domain?" And what specific management capabilities do you want to block?


0

Response Number 7
Name: carl parker
Date: June 15, 2005 at 07:36:41 Pacific
Reply:

I have joined the domain, but I want to keep big brother from watching over me and controlling my workstation.

Thank you for all your help.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows 2000 Forum Home


Sponsored links

Ads by Google


Results for: block domain access via firewall

Blocking msn messenger via ad www.computing.net/answers/windows-2000/blocking-msn-messenger-via-ad/63085.html

join domain from behind firewall www.computing.net/answers/windows-2000/join-domain-from-behind-firewall/61337.html

2nd PC trying to access Windows Update www.computing.net/answers/windows-2000/2nd-pc-trying-to-access-windows-update/23237.html