Can you configure a static port to use with certsrv.msc?

I am trying to use certsrv.msc to connect from my workstation to the CA for administration purposes.  Workstation is Win7, CA is 2008 R2 Enterprise running Enterprise Subordinate on a dedicated box.
I configured a static DCOM port for certsvc by following this article, including bouncing the service and also rebooting the CA box:
http://social.technet.microsoft.com/wiki/contents/articles/1559.how-to-configure-a-static-dcom-port-for-ad-cs.aspx
The static port was opened in the firewall from my workstation to the CA.  We also found that TCP 445 was required, so that has been opened as well, port 135 & other ports normally needed for autoenrollment should be open.  Sniffing the firewall
showed that a random high numbered port that is not the static dcom port is being attempted - this is the only port showing dropped packets & no traffic on the static port.
I am wondering if there is a way to configure a static port for this high-level random port to use with certsrv.msc as I was able to do with the certsvc dcom port?  I am trying to avoid having tens of thousands of network ports wide open going to my
CA...  Thanks in advance!

Hi Steve,
I am sorry that I wasn’t able to find references about restricting certificate services only use one port in the random port range.
However, we can configure RPC dynamic ports allocation to restrict port range. In the meantime, we should keep at least 100 ports open to keep necessary system services running.
More information for you:
How to configure RPC dynamic port allocation to work with firewalls
http://support.microsoft.com/kb/154596/en-us
Service overview and network port requirements for Windows
http://support.microsoft.com/kb/832017/en-au
Firewall Rules for Active Directory Certificate Services
http://blogs.technet.com/b/pki/archive/2010/06/25/firewall-roles-for-active-directory-certificate-services.aspx
Best Regards,
Amy Wang

Similar Messages

  • Can the Gigabit Ethernet LAN Port be used with a Thunderbolt to Gigabit Ethernet adaptor and then to a Thunderbolt Hard Drive as a back up drive?

    Can the Gigabit Ethernet LAN Port be used with a Thunderbolt to Gigabit Ethernet adaptor and then to a Thunderbolt Hard Drive as a back up drive?

    If you use ethernet to connect the two AirPort Extremes together, you'll have Gigabit speeds available at all of the ethernet ports on both routers.
    If you connect the second AirPort Extreme using wireless only and configure the Extreme to "extend a wireless network", then the maximum speeds that the second router can attain will be limited to the capability of the wireless connection. So, if you connect at normal "n" wireless speeds of say 130 Mbps, that will be the maximum speed available at the ethernet ports on the second AirPort Extreme.
    I think you can easily see the difference between Gigabit ethernet, which is 1000 Mbps compared to "n" wireless at 130 Mbps. Even if you can manage to connect at 5 GHz speeds for wireless, the max speed will be in the 300 Mbps range, more than 3 times slower than Gigabit ethernet. Normal "n" speeds will be about 7 times slower than ethernet.
    For streaming high definition video and other demanding sources, you'll need as much bandwidth (speed) as you can get. Ethernet is always the best choice if you can possibly use it. And...there's no wireless interference on an ethernet connection.
    Message was edited by: Bob Timmons

  • Can't configure both WAN ports on 1811 with SDM

    Hi,
    We recently procured an 1811 router to replace a SOHO linksys at a store we service. We needed redundant WAN interfaces to use the DSL as a backup to the main cable connection, and a Linksys RV082, while doing the job when it actually worked, died repeatedly. We decided after looking at the 1811's feature set to just get the Cisco and be done with it and not monkey with SOHO gear anymore.
    Where I'm having difficulty is SDM won't let me configure both WAN interfaces from the GUI, it only allows me to configure one. I have it configured, and the router is working nicely in the test lab but I need to get that other interface configured and failover enabled before I can put this thing into production.
    What am I doing wrong? Do I need to suck it up and learn IOS?
    Thanks,
    Todd Phipps
    Certco, Inc.

    I ended up figuring out the IOS commands to enable one fastethernet port as a primary and the other one as a backup (running both cable and DSL for redundancy; it's a grocery store that runs electronic transactions over IP so 100% availability is a must).
    The trouble I was running into in SDM is that while it would allow me to configure one WAN port through the GUI, the config options for the second one were grayed out. Now that both are configured through IOS the edit buttons for both WAN interfaces appear normally in SDM. It's almost as if Cisco didn't want users to be able to configure both interfaces graphically for initial setup.
    Now just to test it at the site before the store opens to see if the failover works...
    Todd

  • How can you configure a WD external to work with Time Machine??

    I have an 1TB external WD MyBook drive that is connected to my network through my Linksys wireless router and am trying to figure out how to format the drive to use with Time Machine.
    I currently use the drive to store files from both my PC and my MacBook but can't seem to select the drive to use with Time Machine. I figured that I could just format the drive through the Disk Utility program, but the drive doesn't show up in Disk Utility. This may be because it is a drive connected through my router and not directly to my MacBook?!
    Here are a few questions...
    Any ideas on how to format the drive so it will work with Time Machine?
    Once formatted to use with TM, can I still use the drive to store other files from both my Mac and PC? or do I need to partition for this??
    Is it possible to set up an automatic backup schedule that will happen via my home wireless connection?
    Thanks in advance,
    Todd.

    You cannot use the drive with TM as you have it set up. TM will not work with a networked drive except a Time Capsule or a USB drive connected to an Airport Extreme Base Station (current version.)
    If you wish to use this drive for TM backups it must be connected directly to the computer. Other computers on the network can access the drive for TM backups if you turn on file sharing for the drive (select drive, press COMMAND-I, check the box labeled "Shared Folder," click on the Enable button.) The shared drive will have to be mounted on the other computers in order for them to use it as a TM backup drive.

  • Can you configure UCCX E-mail settings using Office 365?

    We would like to utilize this feature, but are wondering if this is possible?

    Disclaimer
    The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
    Liability Disclaimer
    In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
    Posting
    Enable Wireless - Access Points - Global Configuration - Global TCP Adjust MSS
    [edit]
    Oops, didn't read enough of your post.  I see you mention you've already enabled MSS and are asking about UDP.

  • HT3382 With a MacbookAir (mid-2012) using a mini DisplayPort to VGA adapter plugged into the Thunderbolt port, can you configure the external monitor to FULLY display in portrait mode yet keep the built-in display in landscape mode?

    With an 11"-inch Macbook Air (mid-2012) using a mini DisplayPort-to-VGA adapter plugged into the Thunderbolt port:
    Can you configure an extended desktop with an external monitor (20") displaying full portrait mode (1200 x 1600 resolution) and keep the built-in display in landscape?
    I'd like to see something like
    External monitor / Built-in display

    Yes, I can't see why not.
    Just give it a try and report back if you have a problem.

  • Can't configure wireless settings on P1102w using a mac

    Hi there. I can't configure wireless settings on P1102w using a mac. I have it installed with USB just fine but I want to use eprint (with ios airplay). I run the setup utility looking for some wireless setup option, but it never appears. When I finish the install it tells me to go to the eprint website to download eprint. At that site it has me download the firmware update, which I do, and then at the end of that it tells me to go to the eprint website again, which then downloads the firmware update again. It's an endless loop.
    I know I need to get to the built in web server but the config page tells me I don't have an IP address. Which makes sense to me because it hasn't been set up.  I can't for the life of me find how to set up the wireless using the driver software on the Mac OS. I try to follow the manuals instructions, but it looks like it is designed for windows users, and the buttons it tells me to look for just don't exist on the mac HP driver software.
    Can you help?

    Hi,
    The Wireless configuration should be made by using the EWS page, which also accessible from Mac OS over a USB connection through the printer setup.
    You may find the steps listed below:
    Click the Apple icon, then clickSystem Preferences.
    Click Print & Fax.
    Select your printer and click Open Print Queue.
    Click on Printer Setup
    Then select Utility
    Click Open Printer Utility
    Click HTMLConfig. The EWS opens.
    Click the Networking tab
    Then click Wireless from the list on the left
    Under Communication Mode, click Infrastructure, select your network SSID from the Available Network Names (SSID) list, and then click the << button.
    From the Security Mode pop-up menu under Authentication, click WEP or WPA/WPA2. Your selection  depends on which Wireless Security Protocol your network uses.
    Type your WEP/WPA/WPA2 key in the appropriate field, and then click Apply.
    In the confirmation box, click OK and then close the HTML Config and Print Queue windows.
    Once done, allow 3 minutes to fully establish the connection, then unplug the USB.
    Enter Print & Fax and remove the existing USB Print Queue.
    Click the Plus button and add the printer over the network.
    Please let me know of any issue,
    Shlomi
    Say thanks by clicking the Kudos thumb up in the post.
    If my post resolve your problem please mark it as an Accepted Solution

  • Can you print from an iPad 2 using 3G in a home with no computer or wifi by using an iPhone 5 hot spot connection if the printer has been set up in another place with live wifi? I know this question is loaded but my dad lives in a rural area

    Can you print from an iPad 2 using 3G in a home with no other computer or wifi by using an iPhone 5 hot spot connection if the printer has been set up in another place with live wifi? I know this question is loaded but my dad lives in a rural area and is wanting a printer to use occasionally. He doesn't want to deal with a computer and I keep his iPad updated for him at my home.  Please shed some light on this for us PLEASE. Thanks

    In that case, it should be possible. I haven't tried this directly, but I believe it should work.
    You'll need to get an actual AirPrint compatible Printer.
    Check here for a list of Printers you can choose from.
    http://support.apple.com/kb/ht4356
    Once you have the compatible printer, using the Hotspot feature from the iPhone he'll have to create the Wifi bubble form the iPhone, and connect the Printer to that Wifi network.
    Then connect the iPad to that same Wifi network provided by the iPhone. When all that is done, the printer should appear in any of the Apps that can Print under the Action Arrow button.
    For instance in email, pressing the action arrow should show a Print option. In there the printer should appear.
    Alternatively you can simply buy a wireless router and setup the network through there even if there is no internet attached.  Connect the wireless printer to the router network, and connect the iPad or iPhone to that same wifi network to print.

  • How Can You Track Your Ipod If Lost Using The Serial Number

    How Can You Track Your Ipod If Lost Using The Serial Number?

    The find my iphone app has nothong to do with it.
    That app simply allow you to find other devices using your ipod.  It has nothing to do with fining the device on which it is installed.
    If you set up the find my ipod feature that is built into your ipod and the ipod is on and it is connected to wi-fi and it has not been restored, then you may be able to get an approximate street address using icloud.
    Othrewise, it cannot be tracked.

  • Can you share songs and apps but use multiple apple ID's?

    Can you share songs and apps but use multiple apple ID's?

    hmm, that's a trick one! what I would do is go to Messages>preferences>accounts and then select imessages and then select account details and then sign out. Then your wife will need to sign in with her apple id.
    hope this helps!!
    let me know if that works because I've never actually tried it.
    simply adding both of your accounts to be reached at will prove to be faulty because when you reply you can only reply with the one email address. And even if you switch caller id's it probably still won't work. So I think my method would be the easiest way to do that at this time. 

  • Very simple question, how do you configure windows 8.1 to use a SF card as the default install location for software applications?

    Very simple question, how do you configure windows 8.1 to use a SD card / external drive as the default install location for software applications? Primarily interested in apps installed from the windows store. This should be available in the settings
    charm within the windows store. This must have been overlooked in the development of windows 8.1 or is a bug.
    Regards, Bill
    * update
    I've tried modifying this key and the path:
    “HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx”
    http://answers.microsoft.com/en-us/windows/forum/windows_8-windows_store/how-do-you-install-apps-in-windows-8-from-the/c4fbe2a8-fd3d-41c1-b9a6-6f881eed374f
    Also tried using symlinks as detailed here:
    http://social.technet.microsoft.com/Forums/windows/en-US/8eee52c2-db0f-4032-8c72-7cd999e8b41a/windows-8-apps-installing-to-secondary-drive?forum=w8itprogeneral

    Here's some links I've used to try to figure this out:
    http://social.technet.microsoft.com/Forums/windows/en-US/2dfc0cd9-7d1b-41de-abce-e03fb6a5a383/metro-apps-not-working-in-windows-8-pro-x64-after-moving-users-and-programdata-folders?forum=w8itproinstall
    http://social.technet.microsoft.com/Forums/windows/en-US/8eee52c2-db0f-4032-8c72-7cd999e8b41a/windows-8-apps-installing-to-secondary-drive?forum=w8itprogeneral
    http://social.technet.microsoft.com/Forums/windows/de-DE/f5e33ac9-beab-4b99-b3ca-7cb5e6f415e4/how-do-you-change-metro-apps-default-install-location?forum=w8itprogeneral
    Regards, Bill
    The registry method does not work with 8.1.  I found this out the hard way.  Doing it on 8.1 will leave you reinstalling the OS if you didn't do a SRP beforehand.

  • HT1551 can you stream facetime to flat screen using apple tv?

    can you stream facetime to flat screen using apple tv?

    Welcome to the Apple Community.
    Currently you can only mirror it from an iPad2 or iPhone 4s via the Apple TV.

  • HT4994 HAI CAN YOU TELL ME WHICH SIM IS USED IN THIS IMEI **** AND WHICH COUNTRY

    HAI CAN YOU TELL ME WHICH SIM IS USED IN THIS IMEI **** AND WHICH COUNTRY
    <Edited By Host>

    No. Sorry, no one here can help you.
    The only reliable way to determine this info is to call AppleCare.

  • How can I configuration MBean in weblogic server  using the console ?

    How can I configuration MBean in weblogic server using the console ?
    I hear people talking about mbeans in weblogic server I have look in the console I can not find where , or how to do it.
    can some body explain that or a link that explain it, how to do it on the console ?

    Hi,
    Registering Custom MBeans from Admin Console is not yet possible. But yes there are ways to Configure and Utilize Custom MBeans ...
    http://weblogic-wonders.com/weblogic/2010/02/16/registering-and-invoking-custommbeans/
    Thanks
    Jay SenSharma

  • How can you configure mail settings in process chains?

    HI Experts,
    please let me know how can you configure mail settings in process chains?

    Dear Suman,
    To initiate the mails we first need to have SMTP connection. To check the same go to so00 and try sending mails to ur ID. If is successful it states that u have the SMTP access.
    To create mails to Process chains:
    Right Click on the Process varient select the Create Message in the context menu.
    Select the type of mail i.e for successful, Error, Anyways.
    Then follow the screens.
    Note: The recipient type should be Via Internet.
    Hope this helps u.
    Regards,
    Kishore.Pulla

Maybe you are looking for

  • Input field value help

    Hi all, i gt problem to gt the value from the input field:STUDENT-OBJECT_ID, STUDENT-FILE_NAME into my sql statement. I using module. When i delcare a static value objectid = stud. My sql statement can regnoize. How can i gt the objectid base on my i

  • I Cal duplicates

    I Cal duplicates everything onto the first date of the next month. If I delete that, it deletes all the original dates. I have spent hours on this. I am not synced to any other device. This happens where I duplicate or set an ending date on repeat

  • TV Screen Effect

    I want to do an effect, whether I do it directly in Keynote or wherever. I want to insert a picture of an LCD panel and play video on the "screen". So for example, I can take a stock picture of an LCD panel off the Internet. Then I create a shape tha

  • Using threads in a jsp page

    I would like to know wether any one had used threads in a jsp page like one thread gets the data from database while other shows some text saying "getting data from database" Thank you

  • Pur req line item wise block

    Hi Gurus, Is there a way to achieve this specific scenario. Let us say we have five line items on the Pur req.We have setup our approval system in such a way that if the dollar amount is $1000 or more then only the release startegy kicks off. Below 1