Which ports need to be opened between the Domain Controller and Thor Xellerate server for password synchronization?
2 years ago
Originally Published: 2005-01-28
Article Number
000060372
Applies To
Thor Xellerate 7.2.4
Thor Xellerate Password Synchronization DLL
Microsoft Windows 2000 Active Directory
Issue
Which ports need to be opened between the Domain Controller and Thor Xellerate server for password synchronization?
There is a firewall between the Thor Xellerate server and the Domain Controller. When not all the ports are opened, there are communication problems between the Xellerate server and Domain Controller.
Cause
The password synchronization DLL uses CORBA IIOP. The RMI-IIOP communication is done with dynamically assigned ports via the server's IP stack. These ports are temporary; when the connection is terminated, the ports are available for reuse. However, most IP stacks won't reuse the ports until the entire pool of temporary ports are used up. Upon client reconnection, a newly assigned port is created.
Resolution
There are 2 solutions to this problem:

1. Open the entire range of ports on the firewall

2. Use the Wonderwall software recommended by Thor. The Wonderwall is an IIOP proxy which supports firewall traversal via a single static port; the only port that will be needed to opened on the firewall. Contact RSA Security Customer Support to obtain the Wonderwall software.