A network security administrator is configuring internal perimeter firewall rules to enforce compliance for user directory queries between web application servers and a central domain controller. Company policy mandates that all authentication requests across network segments must be cryptographically encrypted over SSL/TLS, and cleartext directory protocol traffic must be dropped. Which of the following port and transport protocol combinations must be explicitly permitted on the firewall to allow compliant directory services traffic?
- TCP port 636Cevap
- BTCP port 389
- CUDP port 636
- DTCP port 3268
Cevap
TCP port 636 must be permitted on the firewall to allow encrypted LDAP (LDAPS) traffic.
Lightweight Directory Access Protocol Secure (LDAPS) uses TCP port 636 to establish an encrypted TLS/SSL tunnel for directory queries and user authentication. This satisfies the requirement to encrypt all identity queries and block unencrypted traffic.
Adım Adım Çözüm
Anahtar Kavram
Lightweight Directory Access Protocol Secure (LDAPS) Port and Transport Identification
Tahmini Süre:1m 30s