Skip to content

Blogging Tom

Technologies and People

  • Home
  • Contact
  • Videos

Tag: Security Hardening

SharePoint Server Hardening, Port 5725

On October 24, 2015October 26, 2015 By Tom ZhangIn Infrastructure, Network, Security HardeningLeave a comment

When hardening SharePoint servers by blocking unnecessary ports, you will need to deal with the port 5725 which is used by user profile synchronization. Two questions emerge:

  1. If we enable Windows Firewall on the servers, on which server do we open the port?
  2. On the hardware firewall, how do we specify the firewall rules, essentially from which server to which server?

On the dedicated TechNet Article for SharePoint Security hardening, you will find the statement below:

“TCP 5725 must be open on the server that runs the Forefront Identity Management agent and is set up to crawl a directory store.”

Obviously, the first question is answered. But what about the second question? If we need to specify the source server, which are the ones? All SharePoint Servers, or just a few?

The answer is:

  • the Application servers that host the User Profile Service Application and
  • the servers that host the Central administration web site.

When these roles are one the same server or on server in the same network zone and the same segment, you don’t have to worry about the rules. But if they communicate through the surveillance of a Firewall, you need to make sure the rules are allowing the traffic. For example, the Central Administration website is hosted on the WFEs which is in a separate network zone from the Application server that hosts the User Profile Synchronization instance. You need to allow traffic from the WFEs to the App server through port 5725. If not, you will even have a problem creating a User Profile Synchronization Connection!

This is the error message you will see:

5725

Of course, if the Central Admin site is hosted on an App server, you will not encounter the issue above.

Advertisement

Follow me on Twitter

My Tweets

Recent Posts

  • Affine Transformation — why 3D matrix for a 2D transformation
  • Vendors’ Unique Position in Change Management
  • Down to the Bottom – Weights Update When Minimizing the Error of the Cost Function for Linear Regression
  • A User Story in an Architect’s Eyes
  • IT Books that Teach You “Best Practices”

Recent Comments

Move search index lo… on Move SharePoint 2013 Search In…
Tom Zhang on SharePoint Three-Tier Network…
Null on SharePoint Three-Tier Network…
Tom Zhang on SharePoint Three-Tier Network…
Null on SharePoint Three-Tier Network…

Archives

  • January 2023
  • December 2020
  • May 2020
  • January 2020
  • July 2018
  • January 2018
  • December 2017
  • March 2017
  • December 2016
  • October 2016
  • July 2016
  • March 2016
  • January 2016
  • November 2015
  • October 2015
  • June 2015
  • April 2015
  • March 2015
  • October 2014
  • August 2014
  • July 2014

Categories

  • Azure
  • Blockchain
  • Book Review
  • Change Management
  • Databases
  • DNS
  • HTML
  • Infrastructure
  • Linear Algebra
  • Machine Learning
  • Network
  • Office 365
  • Office Web Apps
  • Patching
  • PowerShell
  • Project Management
  • Ramdon thoughts
  • Search
  • Security Hardening
  • SharePoint
  • SQL Server
  • UI/UX
  • Uncategorized

Meta

  • Register
  • Log in
  • Entries feed
  • Comments feed
  • WordPress.com

Recent Posts

  • Affine Transformation — why 3D matrix for a 2D transformation
  • Vendors’ Unique Position in Change Management
  • Down to the Bottom – Weights Update When Minimizing the Error of the Cost Function for Linear Regression
  • A User Story in an Architect’s Eyes
  • IT Books that Teach You “Best Practices”

Recent Comments

Move search index lo… on Move SharePoint 2013 Search In…
Tom Zhang on SharePoint Three-Tier Network…
Null on SharePoint Three-Tier Network…
Tom Zhang on SharePoint Three-Tier Network…
Null on SharePoint Three-Tier Network…

Archives

  • January 2023
  • December 2020
  • May 2020
  • January 2020
  • July 2018
  • January 2018
  • December 2017
  • March 2017
  • December 2016
  • October 2016
  • July 2016
  • March 2016
  • January 2016
  • November 2015
  • October 2015
  • June 2015
  • April 2015
  • March 2015
  • October 2014
  • August 2014
  • July 2014

Categories

  • Azure
  • Blockchain
  • Book Review
  • Change Management
  • Databases
  • DNS
  • HTML
  • Infrastructure
  • Linear Algebra
  • Machine Learning
  • Network
  • Office 365
  • Office Web Apps
  • Patching
  • PowerShell
  • Project Management
  • Ramdon thoughts
  • Search
  • Security Hardening
  • SharePoint
  • SQL Server
  • UI/UX
  • Uncategorized

Meta

  • Register
  • Log in
  • Entries feed
  • Comments feed
  • WordPress.com
Create a free website or blog at WordPress.com.
Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.
To find out more, including how to control cookies, see here: Cookie Policy
  • Follow Following
    • Blogging Tom
    • Already have a WordPress.com account? Log in now.
    • Blogging Tom
    • Customize
    • Follow Following
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar
 

Loading Comments...