Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Info

NOTE: Small Business Server (SBS) does not support trusts.

Setting up a Trust between the SoftApp distribution environment and your local AD is necessary for exchanging and updating user data. For the initial addition of users, a bi-directional forest trust is always required. After adding the users to the system, this trust can be converted into a one-way forest trust.


Child pages (Children Display)
excerptTyperich content

Inhoudsopgave

Table of Contents
outlinetrue


Our topology

Afbeeldingsresultaat voor lync resource forest

fig 1. Skype for Business resource forest topology

One-way or Two-way trust relationship?


One-way trustTwo-way trust
Add usersManualAutomatically
SecurityOptimalSub-Optimaal, softapp can read users from your domain


Security

Open the following ports in the firewall towards 192.168.184.0/24

Client Port (s)Server PortService
49152 -65535 / UDP123 / UDPW32Time
49152 -65535 / TCP135 / TCPRPC Endpoint Mapper
49152 -65535 / TCP464 / TCP / UDPKerberos password change
49152 -65535 / TCP49152-65535 / TCPRPC for LSA, SAM, Netlogon (*)
49152 -65535 / TCP / UDP389 / TCP / UDPLDAP
49152 -65535 / TCP636 / TCPLDAP SSL
49152 -65535 / TCP3268 / TCPLDAP GC
49152 -65535 / TCP3269 / TCPLDAP GC SSL
53, 49152 -65535 / TCP / UDP53 / TCP / UDPDNS
49152 -65535 / TCP49152 -65535 / TCPFRS RPC (*)
49152 -65535 / TCP / UDP88 / TCP / UDPKerberos
49152 -65535 / TCP / UDP445 / TCPSMB (**)
49152 -65535 / TCP49152-65535 / TCPDFSR RPC (*)


(*) For information about how to define RPC server ports that are used in the LSA RPC services, see the following Microsoft Knowledge Base articles:

(**) For the operation of the trust this port is not required, it is used for trust creation only. 


Info

Note: External trust 123 / UDP is only required if the Windows Time Service is set to Sync with a server across the external trust.