Skip to content
07 · Domain Controller HardeningPart 4 of 4Intermediate

Firewalling domain controllers: ports, egress, admin access

Build a domain controller firewall policy: required AD ports, restricted RPC, no internet egress, and RDP/WinRM only from Tier 0 PAWs. Measure first.

Florian Amette7 min read

A domain controller has to be reachable by every domain member. That makes people assume it cannot be firewalled. It can. Clients need a known set of authentication and directory ports, but they do not need RDP, WinRM or remote service management. The DC itself almost never needs to start a connection toward a workstation or the internet. Get those three things right and you remove lateral movement onto DCs, coercion relay paths and command-and-control egress in one go.

The DC baseline states the egress principle. This guide turns it into a policy you can deploy. It covers the port matrix, how to measure real traffic before blocking, host and network rules, management access from Tier 0 only, and how to verify that nothing broke.

The port matrix

Split DC traffic into three flows. Each flow gets different sources and different rules.

Clients and member servers to DCs (inbound):

PortProtocolPurpose
53 TCP/UDPDNSName resolution, DC locator SRV records
88 TCP/UDPKerberosAuthentication
123 UDPNTPTime sync (domain hierarchy)
135 TCPRPC Endpoint MapperNetlogon, SAMR, LSA, DRSUAPI lookups
389 TCP/UDPLDAP / CLDAPDirectory queries, DC locator ping
445 TCPSMBSYSVOL, NETLOGON, Group Policy, named-pipe RPC
464 TCP/UDPKerberos kpasswdPassword changes
636 TCPLDAPSLDAP over TLS
3268 / 3269 TCPGlobal CatalogForest-wide searches, UPN logon
49152-65535 TCPDynamic RPCNetlogon, LSA, SAMR, DRS endpoints

DC to DC (replication, both directions): everything above plus the RPC ports used by DRSUAPI and DFSR. Allow full DC-to-DC traffic between DC subnets. Troubleshooting a replication outage caused by an overly clever ACL is not worth it.

Management (Tier 0 only): 3389 (RDP), 5985/5986 (WinRM), 9389 (AD Web Services, used by the ActiveDirectory PowerShell module and ADAC), plus RPC for MMC snap-ins. These come from PAWs or Tier 0 jump hosts only.

Legacy NetBIOS (UDP 137/138, TCP 139) is only needed if you still have NetBIOS-dependent clients. Retire it with the LLMNR and NBT-NS work in disabling LLMNR, NetBIOS and WPAD.

Things people forget

  • ICMP. Group Policy processing and some DC locator checks use ICMP echo to detect slow links. Allow ICMP echo request/reply from client subnets to DCs rather than blocking it and troubleshooting odd GPO behaviour later.
  • IPv6. Windows prefers IPv6 when it is available. If your network rules only cover IPv4, a DC with a link-local or SLAAC address may be reachable in ways your policy never considered. Write rules for both, or deliberately control IPv6 on DC subnets.
  • Read-only DCs in branch or perimeter sites. An RODC needs the replication ports toward a writable DC, but only in one direction for inbound replication. Treat the RODC subnet as less trusted than the core DC subnet and do not let it reach management ports on writable DCs.
  • Other forests. Trusts need Kerberos, LDAP, DNS, SMB and RPC between the DCs of both forests. Scope those rules to the partner's DC addresses, not to their whole network.

Optional: pin RPC services to fixed ports

If your network team insists on narrow rules, you can pin the busiest RPC services to static ports. Microsoft supports these settings, and they need a restart of the affected service (in practice, a DC reboot):

PowerShell
$ntds     = 'HKLM:\SYSTEM\CurrentControlSet\Services\NTDS\Parameters'
$netlogon = 'HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters'
Set-ItemProperty $ntds     -Name 'TCP/IP Port' -Value 50100 -Type DWord   # AD replication / DRSUAPI
Set-ItemProperty $netlogon -Name 'DCTcpipPort' -Value 50101 -Type DWord   # Netlogon
dfsrdiag StaticRPC /port:50102 /Member:DC01.corp.example.com               # DFSR (SYSVOL)

This narrows replication traffic but does not remove the need for the dynamic range, because other RPC interfaces still use it. Treat it as optional.

Measure: what actually talks to your DCs

Do not write a rule set from a port table alone. Before you block anything, turn on firewall logging for allowed and dropped connections on every DC. This should be a GPO setting at Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security > Windows Defender Firewall Properties > Domain Profile > Logging. The PowerShell equivalent, useful for a pilot DC:

PowerShell
Set-NetFirewallProfile -Profile Domain,Private,Public `
    -LogAllowed True -LogBlocked True -LogMaxSizeKilobytes 32767 `
    -LogFileName '%systemroot%\system32\LogFiles\Firewall\pfirewall.log'

Collect two to four weeks of logs, including a month-end and a patch cycle. Then summarise by destination port, source subnet and direction. A quick way to see live outbound sessions a DC is starting:

PowerShell
Get-NetTCPConnection -State Established |
    Where-Object { $_.RemoteAddress -notmatch '^(127\.|::1)' -and $_.LocalPort -gt 1023 } |
    Group-Object RemoteAddress, RemotePort | Sort-Object Count -Descending |
    Select-Object Count, Name -First 40

Expect outbound flows to other DCs, DNS forwarders, your WSUS or patch server, time sources, the SIEM or log collector, backup servers, and PKI CRL/AIA locations. Everything else needs an owner. Monitoring agents and backup tools that "call home" to a vendor cloud are the usual surprises.

Enforce on the network

Implement the core policy on the network firewall or the segmentation platform in front of the DC subnet, so the DC's own local administrators cannot undo it:

Text
# Inbound to DC subnet
ALLOW  client/server subnets -> DCs   53,88,123,135,389,445,464,636,3268,3269,49152-65535
ALLOW  DC subnets            -> DCs   any
ALLOW  Tier 0 PAW subnet     -> DCs   3389,5985,5986,9389 (+ above)
DENY   any                   -> DCs   3389,5985,5986,9389
DENY   any                   -> DCs   any   (log)

# Outbound from DC subnet
ALLOW  DCs -> DC subnets, DNS forwarders, WSUS, NTP, SIEM, backup, CRL/AIA
DENY   DCs -> workstation and user-server subnets  445, 80, 443   (log)
DENY   DCs -> internet                            any            (log)

The outbound deny toward workstation subnets on 445 and 80/443 is what removes most authentication coercion value. A DC that cannot open SMB or HTTP to the attacker's host cannot be relayed from there. If a proxy is required for updates, publish only the Microsoft update endpoints through it, never general browsing.

Enforce on the host

The host firewall is your second layer and your only layer for traffic inside the same subnet. Configure it in a GPO linked only to the Domain Controllers OU, under Computer Configuration > Policies > Windows Settings > Security Settings > Windows Defender Firewall with Advanced Security:

  • Firewall state: On for all profiles. Inbound connections: Block (default). Outbound connections: Allow (default) until you have mapped egress well enough to switch.
  • Under Customize for each profile: Apply local firewall rules: No and Apply local connection security rules: No, so local changes and installers cannot add exceptions.
  • Because local rules are no longer merged, the rules the AD DS role enabled locally stop counting. Add the predefined rule groups to the GPO itself (New Inbound Rule > Predefined): Active Directory Domain Services (which also carries the W32Time NTP rule), DNS Service, DFS Replication, Kerberos Key Distribution Center, Netlogon Service and Core Networking. Pilot this on one DC first.
  • Do not add the predefined Remote Desktop or Windows Remote Management groups, which allow any remote address. Create scoped rules instead.
PowerShell
# Scoped management rules written directly into the DC firewall GPO
$gpo = 'corp.example.com\DC - Firewall'
New-NetFirewallRule -PolicyStore $gpo -DisplayName 'T0 - RDP from PAW' -Direction Inbound `
    -Protocol TCP -LocalPort 3389 -RemoteAddress 10.10.50.0/24 -Action Allow -Profile Domain
New-NetFirewallRule -PolicyStore $gpo -DisplayName 'T0 - WinRM from PAW' -Direction Inbound `
    -Protocol TCP -LocalPort 5985,5986 -RemoteAddress 10.10.50.0/24 -Action Allow -Profile Domain
New-NetFirewallRule -PolicyStore $gpo -DisplayName 'T0 - ADWS from PAW' -Direction Inbound `
    -Protocol TCP -LocalPort 9389 -RemoteAddress 10.10.50.0/24 -Action Allow -Profile Domain

Remember that Windows Firewall processes block rules before allow rules. If you want "deny RDP from everywhere except the PAW subnet", scope the allow rule and remove the broad allows. Do not add a broad block, because it also overrides your scoped allow. Pair network rules with the User Rights Assignment restrictions from the baseline and with the privileged access workstation model, so the PAW subnet really only holds PAWs.

Verify

Test from three places: a standard workstation, a PAW and another DC.

PowerShell
# From a standard workstation: expect True on auth ports, False on management ports
'DC01' | ForEach-Object {
    foreach ($p in 53,88,389,445,636,3268,3389,5985,9389) {
        [PSCustomObject]@{ Port = $p; Open = (Test-NetConnection $_ -Port $p -WarningAction SilentlyContinue).TcpTestSucceeded }
    }
}

# From a DC: confirm no internet egress
Test-NetConnection www.example.org -Port 443

# Replication and locator health after any change
repadmin /replsummary
dcdiag /test:replications /test:netlogons /test:advertising /e /q
nltest /dsgetdc:corp.example.com

On each DC, confirm the effective policy with Get-NetFirewallProfile -PolicyStore ActiveStore and check that no local rules are being merged. Review pfirewall.log and the network firewall's deny logs weekly for the first month. Every legitimate denied flow is either a rule you missed or an agent that should not be talking to a DC.

What it breaks

  • Remote admin tools on ordinary workstations. RSAT consoles, the ActiveDirectory PowerShell module (ADWS on 9389), Enter-PSSession and RDP from helpdesk desktops stop working against DCs. This is the goal. Move that work to PAWs, or delegate it to tools that do not need DC-level access.
  • Agents that call home. Monitoring, EDR and backup agents that reach vendor clouds directly from the DC fail once internet egress is closed. Route them through an approved proxy or a relay in the Tier 0 management zone.
  • DC-initiated connections to members. Remote gpupdate /force from a DC, scripts that push files from a DC to servers, and some legacy software distribution models stop working. None of these should run from a DC.
  • Replication, if you over-narrow. Pinning RPC ports and then forgetting a DC or a new site link is the classic self-inflicted outage. Keep DC-to-DC traffic fully open between DC subnets.
  • Legacy NetBIOS clients that relied on 137-139 lose browsing and name resolution.

Related reading: the DC baseline, defining Tier 0 to decide which management hosts belong in the PAW subnet, and SMB signing enforcement for the traffic you still allow.

Frequently asked questions

Can I restrict the dynamic RPC range on domain controllers?

Yes. You can pin AD replication to a fixed port with the TCP/IP Port value under the NTDS Parameters key, Netlogon with DCTcpipPort, and DFSR with dfsrdiag StaticRPC. Other RPC services still use the dynamic range 49152-65535. Most organisations therefore keep the dynamic range open between DCs and toward clients, but restrict it by source subnet at the network firewall.

Should I block outbound traffic with Windows Defender Firewall on DCs?

Enforce egress at the network layer first, because an attacker with admin rights on a DC can change the host firewall. Host outbound blocking is a useful second layer but is operationally heavy, since every agent, update channel and replication partner needs an explicit rule. Start with network egress control and the host firewall on inbound, then add host outbound rules once you know the traffic well.

Which clients need to reach domain controllers directly?

Every domain-joined device needs DNS, Kerberos, LDAP, SMB for SYSVOL and NETLOGON, and RPC to domain controllers. So you cannot hide DCs from clients. What you can do is limit which ports clients reach, take management protocols such as RDP, WinRM and ADWS away from ordinary subnets, and stop DCs from starting connections outward.

Firewalling domain controllers: ports, egress, admin access

Related guides

NTLM & Legacy Protocols

Enforce LDAP signing and channel binding on DCs

Roll out LDAP signing and channel binding with evidence: collect events 2887, 2889 and 3039, fix clients, then set LdapEnforceChannelBinding safely.

Intermediate