Hi,
if I configure access from lan to vlan where my DC is located, should I select in firewall only service group named: "Windows AD".
Is this enough to have access to all needed services to my windows domain controller, like singing users, joining computers, NTP, etc?
Hello,
Do you have find an answer for your question ? I am in the same case.
Please let me know if you have tested an validated this solution.
Thanks
Hello,
For information in windows AD group Name service you have the following services. (find in attached file windows_AD)
I think you have to add NTP if you when NTP services.
I think with these services the authntication will work fine but I prefere a confirmation, especially when the user change the password after password espiration from active directory.
I'm not sure SMB, SAMBA is necessary for authentication, but you can keep it.
Hello,
I found one more information, in the Windows AD group, you have to open port 464 on UDP and TCP ( it's for Kerberos change/set password). Before check if it's not already open in kerberos service.
Best regards.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1759 | |
1116 | |
766 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.