The Remote Procedure Call (RPC) wird benötigt, damit verschiedene Windows-Prozesse Informationen austauschen können. The following table summarizes the information from the System services ports section. The Computer Browser system service maintains an up-to-date list of computers on your network and supplies the list to programs that request it. A summarized list of services, ports, and protocols required for member computers and domain controllers to inter-operate with one another or for application servers to access Active Directory include but are not limited to the following. The Cluster service controls server cluster operations and manages the cluster database. A cluster is a collection of independent computers that act as a single computer. The Remote Procedure Call (RPC) system service is an interprocess communication (IPC) mechanism that enables data exchange and invocation of functionality that is located in a different process. The Distributed File System Namespaces (DFSN) integrates different file shares that are located on a local area network (LAN) or wide area network (WAN) into a single logical namespace. By default, RPC uses ports in the ephemeral port range (1024-5000) when it assigns ports to RPC applications that have to listen on a TCP endpoint. The ALG FTP plug-in supports these sessions by redirecting all traffic that meets the following criteria to a private listening port in the range of 3000 to 5000 on the loopback adapter: The ALG FTP plug-in then monitors and updates FTP control channel traffic so that the FTP plug-in can forward port mappings through the NAT for the FTP data channels. SSL is an open standard for establishing an encrypted communications channel to help prevent the interception of extremely important information, such as credit card numbers. These ports are also informally known as random RPC ports. To begin, run the following command to query the RPC Port Mapper on the remote machine, this will return the ports in the ephemeral range that the machine is actively listening on for RPC services: RPC does not use only the hard-coded ports that are listed in the table. The Computer Browser service is used by Windows-based computers to view network domains and resources. The Net Logon service uses RPC over named pipes for earlier versions of Windows clients. Indicates the ports and protocols that each service requires for correct operation. The Terminal Services Session Directory system service enables clusters of load-balanced terminal servers to correctly route a user's connection request to the server where the user already has a session running. The Server system service provides RPC support and file sharing, print sharing, and named pipe sharing over the network. Windows Media Services supports a larger variety of control protocols. American National Standards Institute (ANSI), RFC 2349 - Time-out interval, and transfer size options, Distributed File System Replication (if not using FRS for SYSVOL replication), File Replication Service (if not using DFSR for SYSVOL replication), WINS (in Windows Server 2003 SP1 and later versions for backup Active Directory replication operations, if DNS is not working), Certificate Services (required for specific configurations), Distributed File System Namespaces (if using domain-based namespaces). The Remote Storage Notification system service notifies users when they read from or write to files that are available only from a secondary storage media. Port 3702 (UDP) is used to discover the availability of cached content on a client. Stopping this service prevents this notification. ³ Port 5722 is only used on a Windows Server 2008 domain controller or on a Windows Server 2008 R2 domain controller. Trap destinations include the computer name, the IP address, or the Internetwork Packet Exchange (IPX) address of the management system. If you use L2TP with IPsec, you must allow IPsec ESP (IP protocol 50), NAT-T (UDP on port 4500), and IPsec ISAKMP (UDP on port 500) through the router. Erforderlich sind dafür neben dem WMI-Service winmgmt auch DCOM. Die dynamische Portzuweisung (Remote Procedure Call, RPC) wird von Serveranwendungen und Remoteverwaltungsanwendungen wie dem DHCP-Manager (Dynamic Host Configuration Protocol), dem WINS-Manager (Windows Internet Name Service) usw. Windows XP implemented roaming user profile caching as part of the Winlogon process while Windows Vista, Windows Server 2008, and later operating systems use the User Profile Service. Port numbers below 5000 may already be in use by other applications and could cause conflicts with your DCOM application (s). This service has the same firewall requirements as the File and Printer Sharing feature. For a detailed description of RPC, see Remote Procedure Call (RPC). It manages the print queues on the system and communicates with printer drivers and input/output (I/O) components, such as the USB port and the TCP/IP protocol suite. DNS servers are required to locate devices and services that are identified by using DNS names and to locate domain controllers in Active Directory. When SNMP Trap Service is configured for an agent, the service generates trap messages if any specific events occur. For information about the ports that are used by Windows Media Services, see Allocating Ports for Windows Media Services. ICMP is used for slow link detection. The IPAM client UI communicates with the IPAM server to perform remote management. WINS servers communicate with network clients by using NetBIOS name resolution. A Telnet server supports two kinds of authentication and supports the following kinds of terminals: Terminal Services provides a multi-session environment that enables client devices to access a virtual Windows desktop session and Windows-based programs that are running on the server. für \"Remote Registry\", Druckdienste, Backup, Eventlog, Taskplaner und auch Outlook/Exchange bedient sich der Dienste des \"Portmappers\" um die aktuellen Ports für die gewünschten Dienste zu erhalten. Although many services may rely on a particular TCP or UDP port, only one service or process at a time can listen on that port. Die unten besprochenen Werte (und Internet Schlüssel) werden nicht in der Registrierung angezeigt; Sie müssen manuell mit dem Registrierungs-Editor hinzugefügt werden. PortsInternetAvailable REG_SZ Y oder N (Groß-/Kleinschreibung wird nicht berücksichtigt). The events contain diagnostic information in addition to errors that are specific to the source program, the service, or the component. The software distributes data among the nodes of the cluster. When the Internet Connection Sharing feature is enabled, your computer becomes an Internet gateway on the network. This article contains several references to the default dynamic port range. Don't use the port information in this article to configure Windows Firewall. ¹ For more information about how to customize this port, see File Replication Service in the References section. Windows Server 2012 support the initiation of remote group policy update against Windows Server 2012 computers. If IP version 6 (IPv6) is not installed, port 445 communications will also depend on ICMP for name resolution. ASP.NET State Service provides support for ASP.NET out-of-process session states. The TCP/IP Print Server system service enables TCP/IP-based printing by using the Line Printer Daemon (LPD) protocol. Der standardmäßige dynamische Portbereich für TCP/IP hat sich seit Windows Vista und in Windows Server 2008 geändert. The Boot Information Negotiation Layer (BINL) service, the primary component of Remote Installation Server (RIS), answers PXE client requests, checks Active Directory for client validation, and passes client information to and from the server. The Simple Mail Transfer Protocol (SMTP) system service is an email submission and relay agent. If your computer network environment uses Windows Server 2008 R2, Windows Server 2008, Windows 7, or Windows Vista together with versions of Windows earlier than Windows Server 2008 and Windows Vista, you must enable connectivity over both port ranges: Port 5722 is only used on a Windows Server 2008 domain controller or a Windows Server 2008 R2 domain controller; it is not used on a Windows Server 2012 domain controller. System services: System services are programs that load automatically as part of an application's startup process or as part of the operating system startup process. In addition, the Microsoft LDAP client uses ICMP pings to verify that an LDAP server it has a pending request with is still present on the network. Fax Service lets users use either a local fax device or a shared network fax device to send and receive faxes from their desktop programs. The Routing and Remote Access service also provides dial-up and VPN remote access services. System service names: ProfSvc, CscService. Wenn ein Fehler in der Portkonfiguration vorliegt oder unzureichende Ports im Pool vorhanden sind, kann der Endpunktzuordnungsdienst keine RPC-Server mit dynamischen Endpunkten registrieren. Based on the information that is contained in the named log collection setting, the Performance Logs and Alerts service starts and stops each named performance data collection. SNMP Trap Service receives trap messages that are generated by local or by remote SNMP agents. Microsoft customers who deploy servers that are running Windows Server 2008 may have problems that affect RPC communication between servers if firewalls are used on the internal network. The ephemeral port range depends on the server operating system that the client operating system is connected to. The ALG FTP plug-in supports active FTP sessions through the network address translation (NAT) engine that these components use. Event log reports contain information that you can use to diagnose problems. ¹ For more information about how to customize this port, see Domain controllers and Active Directory in the References section. Please note that TMG extends the default dynamic port ranges in Windows Server 2008 R2, Windows 7, Windows Server 2008, and Windows Vista. Es existieren viele Implementierungen dieser Technik, die in der Regel untereinander nicht kompatibel sind. RPC dynamic port allocation will instruct the RPC program to use a particular random port in the range configured for TCP and UDP, based on the … The Routing and Remote Access service provides multiprotocol LAN-to-LAN, LAN-to-WAN, VPN, and NAT routing services. Because of legacy design constraints and evolving license terms and conditions, License Logging may not provide an accurate view of the total number of CALs that are purchased compared to the total number of CALs that are used on a particular server or across the enterprise. TCP/IP and UDP/IP ports that are higher than port 1024 are used. Application Layer Gateway (ALG) plug-ins can open ports and change data (such as ports and IP addresses) that are embedded in packets. Windows domain controllers use the SMTP service for intersite e-mail-based replication. The Windows 2000 version of this service uses Simple Network Time Protocol (SNTP). Fax Service, a Telephony API (TAPI) compliant system service, provides fax capabilities. This means that the client first connects to the FTP server by using the control port. For example, when you open My Network Places on a computer that is running Microsoft Windows 95, a list of domains and computers appears. Active Directory runs under the Lsass.exe process and includes the authentication and replication engines for Windows domain controllers. WINS replication is only required between WINS servers. SNMP performs management services by using a distributed architecture of management systems and agents. Internet Connection Firewall/Internet Connection Sharing, SQL Server: Downlevel OLAP Client Support. You can then rely on other firewall features that dynamically let the service respond through temporary holes on any other port. Original KB number:   832017. If no member is specified, Dfsrdiag.exe uses the local computer. If your computer network environment uses only versions of Windows earlier than Windows Server 2008 and Windows Vista, you must enable connectivity over the low port range of 1025 through 5000. This system service provides NAT, addressing, and name resolution services for all computers on your home network or your small-office network. The Trivial FTP Daemon service implements support for the Trivial FTP Protocol (TFTP) that is defined by the following RFCs: Trivial File Transfer Protocol (TFTP) is an FTP that supports diskless startup environments. License Logging was introduced with Microsoft Windows NT Server 3.51. To successfully apply Group Policy, a client computer must be able to contact a domain controller over the Kerberos, LDAP, SMB, and RPC protocols. These protocols are provided by Internet Information Services (IIS). Remote Procedure Call (RPC) dynamic port allocation is used by server applications and remote administration applications such as Dynamic Host Configuration Protocol (DHCP) Manager, Windows Internet Name Service (WINS) Manager, and so on. Verwenden Sie die in diesem Artikel beschriebene Methode nur, wenn der RPC-Server keine Möglichkeit zum Definieren des Serverports bietet. Port Nummern unter 5000 werden möglicherweise bereits von anderen Anwendungen verwendet und können zu Konflikten mit ihren DCOM-Anwendungen führen. The default data (that is used for active mode FTP) port is automatically set to one port less than the control port. Therefore, if you configure the control port to port 4131, the default data port is port 4130. Die unten beschriebenen RPC-Port Schlüsselwerte befinden sich alle im folgenden Schlüssel in der Registrierung: HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Internet\Entry name Data Type. FTP is the only network protocol that has a plug-in that is included with Windows Server. The Windows Time system service maintains date and time synchronization on all the computers on a network that are running Windows XP or later versions and Windows Server 2003 or later versions. On domain member computers, Net Logon uses RPC over named pipes. Although this information may also apply to Windows XP and to Microsoft Windows 2000 Professional, this article is focused on server-class operating systems. Because portmap provides coordination between RPC services and the port numbers used to communicate with them, it is useful to view the status of current RPC services using portmap when troubleshooting. Gibt eine Reihe von IP-Portbereichen an, die entweder aus allen verfügbaren Ports im Internet oder aus allen Ports bestehen, die nicht über das Internet verfügbar sind. This port is used only by the ISA management MMC during remote server and service status monitoring. All of these systems use SMB. If your computer network environment uses Windows Server 2012 together with versions of Windows earlier than Windows Server 2008 and Windows Vista, you must enable connectivity over both the following port ranges: Contains a brief description of each service. Mit vielen RPC-Servern in Windows können Sie den Serverport in benutzerdefinierten Konfigurationselementen wie Registrierungseinträgen angeben. For example, if you configure a VPN gateway that is behind a filtering router, you will probably You can use the Remote Installation system service to install Windows 2000, Windows XP, and Windows Server 2003 on Pre-Boot Execution Environment (PXE) remote boot-enabled client computers. The Distributed File Replication Service includes the Dfsrdiag.exe command-line tool. Original Version des Produkts:   Windows Server 2012 R2 For information about FTP, see the following resources: For more information about how to plan MADCAP servers, see Checklist: Installing a MADCAP server. Need Required Active Directory Ports for Isolated Environment. Wenn Sie RPC mit TCP/IP oder mit UDP/IP als Transport verwenden, werden eingehende Ports bei Bedarf häufig dynamisch Systemdiensten zugewiesen. The rpcinfo command shows each RPC-based service with port numbers, an RPC program number, a version number, and an IP protocol type (TCP or UDP). The Authentication Service issues ticket granting tickets, and the Ticket-Granting Service issues tickets for connection to computers in its own domain. For information about ports, authentication, and encryption for all data paths that are used by Microsoft Exchange Server, see Network ports for clients and mail flow in Exchange. Ähnlich wie eine Webseite kann sich ein Unternehmen für ihren Dienst einen Port zulegen, sodass die Datenpakete mit Garantie am Bestimmungsort ankommen. For more information about this, see the References section. You can use the Internet Information Services (IIS) Manager snap-in to configure the ports that are used by this service. ¹ Cluster Service UDP traffic over port 3343 requires the Datagram Transport Layer Security (DTLS) protocol, version 1.0 or version 1.2. Beispielsweise wird der neue Registrierungsschlüssel wie folgt angezeigt: Ports: REG_MULTI_SZ: 5000-6000 Print Spooler is the center of the Windows printing subsystem. IPsec Encapsulating Security Protocol (ESP) (IP protocol 50), IPsec Network Address Translator Traversal NAT-T (UDP port 4500), IPsec Internet Security Association and Key Management Protocol (ISAKMP) (UDP port 500), Secure/Multipurpose Internet Mail Extensions (S/MIME). You can receive more information and help planning an Exchange implementation from the following Microsoft websites: For more information, see Configure Outlook Anywhere in Outlook 2013. Use this section to quickly determine which services listen on a particular port. Domain controllers, client computers, and application servers require network connectivity to Active Directory over specific hard-coded ports. This port was originally part of the TACO project. Although the Routing and Remote Access service can use all the following protocols, the service typically uses only a few of them. Port 445 is used by DFSR only when creating a new empty replicated folder. The Print Spooler service uses RPC over named pipes. The TFTP service listens on UDP port 69, but it responds from a randomly allocated high port. This port is also used for intra-array traffic. FRS is the default replication engine that is used to replicate the contents of the SYSVOL folder between Windows 2000-based domain controllers and Windows Server 2003-based domain controllers that are located in a common domain. This service helps you locate network resources by using NetBIOS names. The License Logging service uses RPC over named pipes. If your computer network environment uses only Windows Server 2012, you must enable connectivity over the high port range of 49152 through 65535. When this service runs, it relies on the WORKSTATION service and on the Local Security Authority service to listen for incoming requests. The HTTP SSL system service enables IIS to perform SSL functions. ³ This protocol is required only by Windows XP and Windows Server 2003 acting as clients. Wenn Y ist, werden die Prozesse, die die Standardeinstellung verwenden, Ports aus der Gruppe der Ports zugewiesen, die im Internet verfügbar sind (wie zuvor definiert). Zahlreiche integrierte Windows-Komponenten verwenden RPC. Earlier versions of Windows-based programs, such as My Network Places, the net view command, and Windows Explorer, all require browsing capability. Der Netlogon-Dienst konnte die Authz-RPC-Schnittstelle nicht hinzufügen. The default HTTP port is TCP 5985, and the default HTTPS port is TCP 5986. Mit vielen RPC-Servern in Windows können Sie den Serverport in benutzerdefinierten Konfigurationselementen wie Registrierungseinträgen angeben.