Which ports are required in order to authenticate against a ldap server in another domain which is behind a firewall


I have a Linux domain running with sssd, let's call this domain NJ.

I'd like machines on the NJ domain to be able to authenticate against an Active Directory ldap server which resides on a different domain (called NY) which is behind a firewall.

Would it be enough to allow only port 389 between both domains or are there any other ports which are required in order for the machines on the NJ domain to authenticate against ldap servers in the NY domain?

Best Answer

As long as it LDAP auth only (and not AD/Kerberos etc.), 389 should be sufficient.