3 Ensure that each ES has a valid, fully qualified domain name (FQDN) and that the domain portion
matches the domain for the registered windows domain.
4 Ensure that each ES is configured with one or more valid DNS servers that can fully resolve (both A
and PTR records) each ES.
5 Ensure that the following ports on the domain controller/active directory (DC/AD) servers are
available from quarantine:
88
■
389
■
135-139
■
1025
■
Sentriant AG will then
lookup
own DNS server used for quarantined devices.
For example:
_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.lvh.com. 86400 IN SRV 0 100 88
dc01.lvh.com
_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.lvh.com. 86400 IN SRV 0 100 389
dc01.lvh.com
Sentriant AG Software Users Guide, Version 5.3
the Kerberos and LDAP services, and resolve those services within its
Quarantined Networks
219