Re: [Freeipa-users] ipa ports

2012-05-24 Thread Martin Kosek
On Wed, 2012-05-23 at 19:27 -0400, Dmitri Pal wrote: On 05/23/2012 05:40 PM, Jan-Frode Myklebust wrote: We have quite strict firewalls, so I need to specify the IPA network ports accurately. So, we have now opening for: 80/tcp, 88/tcp, 389/tcp, 443/tcp, 464/tcp, 636/tcp 88/udp,

Re: [Freeipa-users] ipa ports

2012-05-24 Thread Jan-Frode Myklebust
On Thu, May 24, 2012 at 10:50:23AM +0200, Martin Kosek wrote: I suppose you don't need to open 7389/tcp for all clients unless you want them to be able to run LDAP search against dogtag backend LDAP database. I don't see why I would want that, so I'll just open it between the ipa-servers for

[Freeipa-users] ipa ports

2012-05-23 Thread Jan-Frode Myklebust
We have quite strict firewalls, so I need to specify the IPA network ports accurately. So, we have now opening for: 80/tcp, 88/tcp, 389/tcp, 443/tcp, 464/tcp, 636/tcp 88/udp, 464/udp in to our first IPA server. Now I'm in the process of configuring the first replica. Is there any

Re: [Freeipa-users] ipa ports

2012-05-23 Thread Dmitri Pal
On 05/23/2012 05:40 PM, Jan-Frode Myklebust wrote: We have quite strict firewalls, so I need to specify the IPA network ports accurately. So, we have now opening for: 80/tcp, 88/tcp, 389/tcp, 443/tcp, 464/tcp, 636/tcp 88/udp, 464/udp in to our first IPA server. Now I'm in the