Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Will Terminal Server Licensing fail if Port 139 is closed on Firew

Reply
Thread Tools Display Modes

Will Terminal Server Licensing fail if Port 139 is closed on Firew

 
 
Klay
Guest
Posts: n/a

 
      04-28-2009
We are expecting to close port 139 on all physical routers/firewalls and have
been told that Terminal Server Licensing may fail. We serve TS licenses from
one server to several other servers over a WAN. To avoid this we are
attempting to implement IPSec between servers. With the servers tunneling
through IPSec we are hoping to tunnel, port 139 requests past the physical
routers. The router would normally filter that out, and allow the 2003
Server to accept request for port 139 (port 139 not blocked on the servers
yet). Is this a workable solution? Also, if port 139 is blocked on the
physical server will that create later problems?
 
Reply With Quote
 
 
 
 
Anthony [MVP]
Guest
Posts: n/a

 
      05-01-2009
In answer to the subject, here is the MS doc specifying ports for TS
Licensing:

http://support.microsoft.com/kb/832017

Note Terminal Services Licensing offers its services by using RPC over named
pipes. This service has the same firewall requirements as those of the "File
and Printer Sharing" feature.

If you block RPC then not much will work over the WAN. If you use IPSec for
all server communication, then the servers will be able to communicate with
each other, but clients will not communicate with the servers over the WAN.

Instead at the routers/firewalls you could do something like allow servers
to communicate with servers, but not allow clients to communicate with
remote servers except through specified ports e.g for mail, RDP, Citrix,
http etc.

Anthony
http://www.airdesk.com



"Klay" <> wrote in message
news:6AB71833-51CC-458D-AD54-...
> We are expecting to close port 139 on all physical routers/firewalls and
> have
> been told that Terminal Server Licensing may fail. We serve TS licenses
> from
> one server to several other servers over a WAN. To avoid this we are
> attempting to implement IPSec between servers. With the servers tunneling
> through IPSec we are hoping to tunnel, port 139 requests past the physical
> routers. The router would normally filter that out, and allow the 2003
> Server to accept request for port 139 (port 139 not blocked on the servers
> yet). Is this a workable solution? Also, if port 139 is blocked on the
> physical server will that create later problems?


 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How to setup terminal services to remote access from outside firew ghutnick Windows Server 3 05-19-2006 08:02 AM
RE: Licensing server for Terminal Server Licensing is not issuing lice Bill Peng [MSFT] Windows Small Business Server 0 04-14-2005 07:50 AM
Licensing for Terminal Server Karl Windows Server 1 11-04-2004 05:09 PM
Terminal Server Licensing Nancy Windows Small Business Server 1 08-20-2004 05:34 PM
port 4125 closed on my server ? Jéjé Windows Small Business Server 4 03-04-2004 10:35 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59