[Migrated from MSDN Exchange Dev] DAG Over firewall

Yuki Sun-MSFT 41,046 Reputation points Microsoft Vendor
2020-10-30T05:14:14.253+00:00

[Note] This thread was originally posted on MSDN. As the MSDN Exchange Dev forum mainly focuses on Exchange developer questions and the TechNet Exchange forums for Non-developer Exchange has been locked down and transitioned to Microsoft Q&A for support, we manually migrated this one to Microsoft Q&A platform to continue the discussion.

[MSDN thread link] DAG Over firewall

[Original post]
Good morning to all,

I need to set up a database availability group on several sites. In each site there are two MAILBOX Exchange Server 2016 servers. The sites are protected by firewalls.

I would like to have the list of ports to ensure good communication between the DAG members.

Thank you in advance.

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,604 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Yuki Sun-MSFT 41,046 Reputation points Microsoft Vendor
    2020-10-30T05:29:18.443+00:00

    Hi,

    To the best of my knowledge, it's NOT suggested to restrict the network traffic between any internal Exchange servers. And according to the ground rule in the following official document, if you have firewalls that may restrict the network traffic, you'll need to configure rules that allow free and unrestricted communication between these servers:
    Network ports for clients and mail flow in Exchange

    36187-1.png

    Moreover, the blog below also mentions that "a rule allowing 'ANY/ANY' port and protocol communication must be in place allowing free communication between Exchange servers as well as between Exchange servers and domain controllers":
    Exchange, Firewalls, and Support… Oh, my!
    36233-2.png

    Hope you can find the above information helpful.


    If an Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.