This message was deleted.
# citrix-vad
s
This message was deleted.
r
DDC to DDC or DDC to AD for example?
f
If you dont mind an indirect reply, all poort requirements are spelled out in this master document: v=https://docs.citrix.com/en-us/tech-zone/build/tech-papers/citrix-communication-ports.html
r
I win!!!
😀 3
r
HAHAHA
That's funny, we all three put the same link in
f
Does that qualify as triple fact checking?
r
it IS the best link
r
yea it is
n
@Ray Davis DDC to AD
its not in the doc you sent me.
the client and i checked
r
Without looking in doc. I would say 135 ,389.636
r
DDC to AD would just be regular active directory ports, which are like 10000 of them
r
But Ryan has a good point.
n
i am dumba$$
i found it for SF
but not DDC to Domain Controller
r
f

https://docs.citrix.com/en-us/tech-zone/learn/downloads/diagrams-posters_virtual-apps-and-desktops_poster.png

👍 2
💯 1
r
Well that is 2008R2, but hopefully you get the point.
n
wow, not even carl has them listed - https://www.carlstalhood.com/netscaler-firewall-rules/#xenapp ...how could that be?
r
Honestly, It's because most of it is a industry standard now I would say. Most FW have a basic rule set for AD DS in the FW defaults.
n
thanks for the feedback.
i will submit 389/636.
thats what i see on the poster
r
if that's all you open, you're going to have a bad time
r
firewall between domain members is a nightmare, imo
by the time you open all the ports, it's not secure anyway, so what's the fucking point?
🤣 1
r
I bet you know first hand for sure.
r
and i just mean, basic SPI... now if you have some Layer7 inspection there, it's better
but if you're just going to do SPI between them, it's pointless.
f
I suppose its a matter of perspective... Assume the org already opens the necessary ports for a member server to talk to a domain controller, what additional ports would be necessary on a DDC... As opposed to what are all ports necessary for the member server... In the first case the answer really is nothing additional since 389/636 (at least 636 in hyper secure environments) should be open already
n
isn't 636 legacy
f
636 is secure ldap
m
If anyone finds incorrect ports in the document, let me know and we can get them fixed 🙂
👌 1
n
will do! thanks