Relación de puertos usados por Exchange 2010
Hoy queria poner la relación de puertos de comunicación que utiliza Exchange 2010, ya que en muchas ocasiones en nuestras compañias tenemos diversos Firewalls donde por seguridad, no estan abiertos todos los puertos, y buscando en ocasiones es dificil encontrar la relación completa de puertos usados por Exchange, Controladores de Dominio, CRM Dynamics, etc… Aquí pongo los usados por Exchange2010, por cada uno de los roles.
Rol de Hub transport:
Data path | Required ports | Default authentication | Supported authentication | ||
Hub Transport server to Hub Transport server | 25/TCP (SMTP) | Kerberos | Kerberos | ||
Hub Transport server to Edge Transport server | 25/TCP (SMTP) | Direct trust | Direct trust | ||
Edge Transport server to Hub Transport server | 25/TCP (SMTP) | Direct trust | Direct trust | ||
Edge Transport server to Edge Transport server | 25/TCP SMTP | Anonymous, Certificate | Anonymous, Certificate | ||
Mailbox server to Hub Transport server via the Microsoft Exchange Mail Submission Service | 135/TCP (RPC) | NTLM. If the Hub Transport and the Mailbox server roles are on the same server, Kerberos is used. | NTLM/Kerberos | ||
Hub Transport to Mailbox server via MAPI | 135/TCP (RPC) | NTLM. If the Hub Transport and the Mailbox server roles are on the same server, Kerberos is used. | NTLM/Kerberos | ||
Unified Messaging server to Hub Transport server | 25/TCP (SMTP) | Kerberos | Kerberos | ||
Microsoft Exchange EdgeSync service from Hub Transport server to Edge Transport server | 50636/TCP (SSL) | Basic | Basic | ||
Active Directory access from Hub Transport server | 389/TCP/UDP (LDAP), 3268/TCP (LDAP GC), 88/TCP/UDP (Kerberos), 53/TCP/UDP (DNS), 135/TCP (RPC netlogon) | Kerberos | Kerberos | ||
Active Directory Rights Management Services (AD RMS) access from Hub Transport server | 443/TCP (HTTPS) | NTLM/Kerberos | NTLM/Kerberos | ||
SMTP clients to Hub Transport server (for example, end-users using Windows Live Mail) | 587 (SMTP) | NTLM/Kerberos | NTLM/Kerberos | ||
25/TCP (SMTP) |
Rol Maibox:
Data path | Required ports | Default authentication | Supported authentication | ||
Active Directory access | 389/TCP/UDP (LDAP), 3268/TCP (LDAP GC), 88/TCP/UDP (Kerberos), 53/TCP/UDP (DNS), 135/TCP (RPC netlogon) | Kerberos | Kerberos | ||
Admin remote access (Remote Registry) | 135/TCP (RPC) | NTLM/Kerberos | NTLM/Kerberos | ||
Admin remote access (SMB/File) | 445/TCP (SMB) | NTLM/Kerberos | NTLM/Kerberos | ||
Availability Web service (Client Access to Mailbox) | 135/TCP (RPC) | NTLM/Kerberos | NTLM/Kerberos | ||
Clustering | 135/TCP (RPC) See Notes on Mailbox Servers after this table. | NTLM/Kerberos | NTLM/Kerberos | ||
Content indexing | 135/TCP (RPC) | NTLM/Kerberos | NTLM/Kerberos | ||
Log shipping | 64327 (customizable) | NTLM/Kerberos | NTLM/Kerberos | ||
Seeding | 64327 (customizable) | NTLM/Kerberos | NTLM/Kerberos | ||
Volume shadow copy service (VSS) backup | Local Message Block (SMB) | NTLM/Kerberos | NTLM/Kerberos | ||
Mailbox Assistants | 135/TCP (RPC) | NTLM/Kerberos | NTLM/Kerberos | ||
MAPI access | 135/TCP (RPC) | NTLM/Kerberos | NTLM/Kerberos | ||
Microsoft Exchange Active Directory Topology service access | 135/TCP (RPC) | NTLM/Kerberos | NTLM/Kerberos | ||
Microsoft Exchange System Attendant service legacy access (Listen to requests) | 135/TCP (RPC) | NTLM/Kerberos | NTLM/Kerberos | ||
Microsoft Exchange System Attendant service legacy access to Active Directory | 389/TCP/UDP (LDAP), 3268/TCP (LDAP GC), 88/TCP/UDP (Kerberos), 53/TCP/UDP (DNS), 135/TCP (RPC netlogon) | Kerberos | Kerberos | ||
Microsoft Exchange System Attendant service legacy access (As MAPI client) | 135/TCP (RPC) | NTLM/Kerberos | NTLM/Kerberos | ||
Offline address book (OAB) accessing Active Directory | 135/TCP (RPC) | Kerberos | Kerberos | ||
Outlook accessing OAB | 80/TCP, 443/TCP (SSL) | NTLM/Kerberos | NTLM/Kerberos | ||
Recipient Update Service RPC access | 135/TCP (RPC) | Kerberos | Kerberos | ||
Recipient update to Active Directory | 389/TCP/UDP (LDAP), 3268/TCP (LDAP GC), 88/TCP/UDP (Kerberos), 53/TCP/UDP (DNS), 135/TCP (RPC netlogon) | Kerberos | Kerberos |
Rol CAS:
Data path | Required ports | Default authentication | Supported authentication | ||
Active Directory access | 389/TCP/UDP (LDAP), 3268/TCP (LDAP GC), 88/TCP/UDP (Kerberos), 53/TCP/UDP (DNS), 135/TCP (RPC netlogon) | Kerberos | Kerberos | ||
Autodiscover service | 80/TCP, 443/TCP (SSL) | Basic/Integrated Windows authentication (Negotiate) | Basic, Digest, NTLM, Negotiate (Kerberos) | ||
Availability service | 80/TCP, 443/TCP (SSL) | NTLM/Kerberos | NTLM, Kerberos | ||
Outlook Web App | 80/TCP, 443/TCP (SSL) | Forms Based Authentication | Basic, Digest, Forms Based Authentication, NTLM (v2 only), Kerberos, Certificate | ||
POP3 | 110/TCP (TLS), 995/TCP (SSL) | Basic, Kerberos | Basic, Kerberos | ||
IMAP4 | 143/TCP (TLS), 993/TCP (SSL) | Basic, Kerberos | Basic, Kerberos | ||
Outlook Anywhere (formerly known as RPC over HTTP ) | 80/TCP, 443/TCP (SSL) | Basic | Basic or NTLM |
Rol Mensajería Unificada:
Data path | Required ports | Default authentication | Supported authentication | ||
Active Directory access | 389/TCP/UDP (LDAP), 3268/TCP (LDAP GC), 88/TCP/UDP (Kerberos), 53/TCP/UDP (DNS), 135/TCP (RPC netlogon) | Kerberos | Kerberos | ||
Unified Messaging Phone interaction (IP PBX/VoIP Gateway) | 5060/TCP , 5065/TCP, 5067/TCP (unsecured), 5061/TCP, 5066/TCP, 5068/TCP (secured), a dynamic port from the range 16000-17000/TCP (control), dynamic UDP ports from the range 1024-65535/UDP (RTP) | By IP address | By IP address, MTLS | ||
Unified Messaging Web Service | 80/TCP, 443/TCP (SSL) | Integrated Windows authentication (Negotiate) | Basic, Digest, NTLM, Negotiate (Kerberos) | ||
Unified Messaging server to Client Access server | 5075, 5076, 5077 (TCP) | Integrated Windows authentication (Negotiate) | Basic, Digest, NTLM, Negotiate (Kerberos) | ||
Unified Messaging server to Client Access server (Play on Phone) | Dynamic RPC | NTLM/Kerberos | NTLM/Kerberos | ||
Unified Messaging server to Hub Transport server | 25/TCP (TLS) | Kerberos | Kerberos | ||
Unified Messaging server to Mailbox server | 135/TCP (RPC) | NTLM/Kerberos | NTLM/Kerberos |
Un Saludo,