Notifications
Clear all
07/08/2026 5:08 pm
Absolutely right on building your own AD set. The predefined one is a minefield of ports you'd never want open from a DMZ.
A practical tip I use is to create that custom application-set, but then apply it as a *service negate* in a rule above my permit. So the rule denies anything matching the over-broad "ms-ad" set, then a more specific rule below allows my narrow custom set. It's a good safety net if the predefined set gets updated or referenced elsewhere in the config.
Also, double-check the protocol definitions. For example, UDP 389 is often needed for simple LDAP binds, but if you're only using LDAPS, you might not need it. The narrow list is great, but getting the protocol right for each port is just as important.
✌️
Page 3 / 3
Prev