An enterprise network administrator is troubleshooting directory service integration between an internal web proxy and an Active Directory Domain Controller. Authentication using implicit SSL encryption (LDAPS) over TCP port 636 functions correctly. However, automated directory synchronization tasks configured on the proxy to use explicit TLS encryption (STARTTLS) fail to establish a secure connection. Network packet captures confirm that the proxy initiates communication over the default unencrypted LDAP port before issuing the STARTTLS upgrade command, but traffic is blocked by an intermediate firewall ACL. Which of the following transport protocols and destination port combinations must be permitted on the firewall to allow STARTTLS directory synchronization to succeed?
- TCP port 389Answer
- BUDP port 389
- CTCP port 636
- DTCP port 3269