GPMC open ports to PDCe?


i have single domain forest multiple firewalls between domain controllers , network segments, multiple versions of windows server, @ least 1 of each of 2003, 2008, 2008r2 , 2012.

the domain running on windows server 2008 in windows server 2003 mode.

i have firewall rules in place allow domain controller domain controller replication, authentication , access - these working.

one of network tiers 'management tier' number of servers running in it. tier has 2 domain controllers in it, date , working correctly, no errors.

i have installed gpmc on windows 2012 server in tier, , can manage group policies. cannot manage 'windows firewall advanced security' , 'advanced audit policy configuration' - errors when try open these nodes within gpmc.

windows firewall advanced security fails with: error occurred while trying open policy, specified domain either not exist or not contacted. code 0c54b

advanced audit policy configuration fails with: severe error occurred has caused advanced audit configuration unload. following messages can debug error: specified domain either not exist or not contacted. (exception hresult: 0x8007054b).

and question: gpmc need able communicate pdce directly itself? or sufficient communicate local domain controller? if gpmc needs talk pdce directly, ports use?




by default, gpmc talks pdce. can specify different dc right clicking on the  "domain" node in gpmc. doesn't in aspects - gp elements spuriously still talk pdce (that's error seem encounter).

which ports? usual ones - 88, 389, 3268, 445, 135 , dynamic rpc should trick.


martin

no not evil, if know doing: or bad gpos?
, if bothers me - coke bottle design refreshment :))

restore forum design - user defined cascading style sheet!



Windows Server  >  Group Policy



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group