Skip to content

Blogging Tom

Technologies and People

  • Home
  • Contact
  • Videos

Category: Security Hardening

SharePoint Server Hardening, Port 5725

On October 24, 2015October 26, 2015 By Tom ZhangIn Infrastructure, Network, Security HardeningLeave a comment

When hardening SharePoint servers by blocking unnecessary ports, you will need to deal with the port 5725 which is used by user profile synchronization. Two questions emerge:

  1. If we enable Windows Firewall on the servers, on which server do we open the port?
  2. On the hardware firewall, how do we specify the firewall rules, essentially from which server to which server?

On the dedicated TechNet Article for SharePoint Security hardening, you will find the statement below:

“TCP 5725 must be open on the server that runs the Forefront Identity Management agent and is set up to crawl a directory store.”

Obviously, the first question is answered. But what about the second question? If we need to specify the source server, which are the ones? All SharePoint Servers, or just a few?

The answer is:

  • the Application servers that host the User Profile Service Application and
  • the servers that host the Central administration web site.

When these roles are one the same server or on server in the same network zone and the same segment, you don’t have to worry about the rules. But if they communicate through the surveillance of a Firewall, you need to make sure the rules are allowing the traffic. For example, the Central Administration website is hosted on the WFEs which is in a separate network zone from the Application server that hosts the User Profile Synchronization instance. You need to allow traffic from the WFEs to the App server through port 5725. If not, you will even have a problem creating a User Profile Synchronization Connection!

This is the error message you will see:

5725

Of course, if the Central Admin site is hosted on an App server, you will not encounter the issue above.

Follow me on Twitter

My Tweets

Recent Posts

  • Video Classification using CNN+ RNN
  • IoT LoRaWAN Payload Decoding
  • General Regression Neural Network (GRNN) Illustrated in Excel
  • Parameter Redundancy in Large Language Models
  • Embeddings — everything can be a vector

Recent Comments

Unknown's avatarMove search index lo… on Move SharePoint 2013 Search In…
Tom Zhang's avatarTom Zhang on SharePoint Three-Tier Network…
Null's avatarNull on SharePoint Three-Tier Network…
Tom Zhang's avatarTom Zhang on SharePoint Three-Tier Network…
Null's avatarNull on SharePoint Three-Tier Network…

Archives

  • October 2023
  • July 2023
  • January 2023
  • December 2020
  • May 2020
  • January 2020
  • July 2018
  • January 2018
  • December 2017
  • March 2017
  • December 2016
  • October 2016
  • July 2016
  • March 2016
  • January 2016
  • November 2015
  • October 2015
  • June 2015
  • April 2015
  • March 2015
  • October 2014
  • August 2014
  • July 2014

Categories

  • Azure
  • Blockchain
  • Book Review
  • Change Management
  • Databases
  • DNS
  • HTML
  • Infrastructure
  • Large Language Models
  • Linear Algebra
  • Machine Learning
  • Network
  • Office 365
  • Office Web Apps
  • Patching
  • PowerShell
  • Project Management
  • Ramdon thoughts
  • Search
  • Security Hardening
  • SharePoint
  • SQL Server
  • UI/UX
  • Uncategorized

Meta

  • Create account
  • Log in
  • Entries feed
  • Comments feed
  • WordPress.com

Recent Posts

  • Video Classification using CNN+ RNN
  • IoT LoRaWAN Payload Decoding
  • General Regression Neural Network (GRNN) Illustrated in Excel
  • Parameter Redundancy in Large Language Models
  • Embeddings — everything can be a vector

Recent Comments

Unknown's avatarMove search index lo… on Move SharePoint 2013 Search In…
Tom Zhang's avatarTom Zhang on SharePoint Three-Tier Network…
Null's avatarNull on SharePoint Three-Tier Network…
Tom Zhang's avatarTom Zhang on SharePoint Three-Tier Network…
Null's avatarNull on SharePoint Three-Tier Network…

Archives

  • October 2023
  • July 2023
  • January 2023
  • December 2020
  • May 2020
  • January 2020
  • July 2018
  • January 2018
  • December 2017
  • March 2017
  • December 2016
  • October 2016
  • July 2016
  • March 2016
  • January 2016
  • November 2015
  • October 2015
  • June 2015
  • April 2015
  • March 2015
  • October 2014
  • August 2014
  • July 2014

Categories

  • Azure
  • Blockchain
  • Book Review
  • Change Management
  • Databases
  • DNS
  • HTML
  • Infrastructure
  • Large Language Models
  • Linear Algebra
  • Machine Learning
  • Network
  • Office 365
  • Office Web Apps
  • Patching
  • PowerShell
  • Project Management
  • Ramdon thoughts
  • Search
  • Security Hardening
  • SharePoint
  • SQL Server
  • UI/UX
  • Uncategorized

Meta

  • Create account
  • Log in
  • Entries feed
  • Comments feed
  • WordPress.com
Create a free website or blog at WordPress.com.
Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.
To find out more, including how to control cookies, see here: Cookie Policy
  • Subscribe Subscribed
    • Blogging Tom
    • Already have a WordPress.com account? Log in now.
    • Blogging Tom
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar
 

Loading Comments...