Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Yes. On supported Windows Server domain controllers, assign the AD DS (DRS) RPC endpoint a fixed TCP port by creating the TCP/IP Port DWORD under HKLMSYSTEMCurrentControlSetServicesNTDSParameters. Restart each participating domain controller, then permit TCP 135 (the RPC Endpoint Mapper) and the selected static port. For example, using TCP 53211 means allowing both 135 and 53211 between the relevant domain controllers. A single NTDS port does not cover Netlogon, SYSVOL replication, DNS, Kerberos, LDAP, SMB, or other domain-controller traffic.
How the connection works
AD DS replication uses Microsoft RPC. The source DC first contacts the destination DC’s RPC Endpoint Mapper on TCP 135. The mapper returns the port registered by the Directory Replication Service (DRS) interface; replication payloads then use that endpoint.
Source DC --TCP 135--> Destination DC (RPC Endpoint Mapper)
Source DC --TCP 53211--> Destination DC (NTDS/DRS)
Therefore, the instruction “set a static port and block 135” is incorrect. Blocking 135 prevents endpoint discovery and commonly causes RPC errors 1722 or 1753. See Microsoft’s static AD RPC guidance and domain-controller firewall matrix.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Plan the change
- Apply the setting to every DC that must communicate across the restricted firewall path. Replication is bidirectional and topology-dependent.
- Choose an unused, documented TCP port approved by your organization. Microsoft does not mandate a universal number; 53211 is only an example.
- Check local listeners and service assignments on every DC. Do not reuse the port for Netlogon.
- Confirm routing, DNS resolution, firewall ownership, and a restart/change window.
- Decide whether Netlogon, DFSR/FRS, or client RPC traffic also crosses the boundary; those services require separate planning.
Configure a static NTDS replication port
Registry Editor
- Sign in to the domain controller with administrative rights and open Registry Editor.
- Go to
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesNTDSParameters. - Create or edit a DWORD (32-bit) Value named
TCP/IP Port. - Choose Decimal and enter the selected port, such as
53211. - Restart the computer. The NTDS service must restart before the value takes effect.
Back up the registry and use normal change control; an incorrect registry edit can make a server or service unusable.
#1 Best Overall
- PLUG-AND-PLAY GIGABIT MANAGED SWITCH: 8 x 1Gbps auto-negotiating ports work the moment you plug in — full-gigabit speed over Cat5e/Cat6 cabling.
- MANAGED, WITHOUT THE COMPLEXITY: Easy Smart web GUI on Windows, Mac or Linux — no app or Windows-only utility, unlike many competing switches.
- SEGMENT & PRIORITIZE TRAFFIC: Up to 64 VLANs, QoS, IGMP snooping and port mirroring keep voice, video and data fast, secure and organized.
- BUILT-IN PROTECTION: Auto DoS prevention, loop detection, broadcast storm control and cable test keep your network stable and easy to troubleshoot.
- RELIABLE 24/7 BACKBONE: Rugged fanless metal housing runs cool and silent at 0 dBA — the managed switch trusted in homes, offices and small business.
Command line
reg add "HKLMSYSTEMCurrentControlSetServicesNTDSParameters" ^
/v "TCP/IP Port" /t REG_DWORD /d 53211 /f
shutdown /r /t 0
Repeat the configuration on each applicable DC, changing the value only if your design deliberately assigns different destination ports and matching firewall rules. A consistent port simplifies operations.
Allow the required firewall paths
For the example above, permit the relevant DC addresses or subnets—not the entire network—to reach:
| Port | Purpose |
|---|---|
| TCP 135 | RPC Endpoint Mapper |
| TCP 53211 | Static NTDS/DRS replication endpoint |
Replication initiations can occur in either direction, so site firewalls and host firewalls normally need reciprocal DC-to-DC rules. Check network ACLs, VPN/security appliances, Windows Defender Firewall, and endpoint-security products.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallExample inbound Windows Defender Firewall rules (replace the addresses with approved DC IPs or subnets):
Rank #2
- 8 Gigabit Ethernet Ports: Expand your network with 8 high-speed ethernet ports for enhanced connectivity and performance
- Easy Smart Management: Manage and configure your network effortlessly via a web interface or free software
- Support VLAN: Segment traffic with up to 32 VLANs simultaneously out of 4K VLAN IDs for better security
- Network Monitoring: Monitor your network effectively with port mirroring, loop prevention, and cable diagnostics
- IGMP Snooping: Enhances multicast application performance for improved network efficiency
New-NetFirewallRule `
-DisplayName "AD DS Replication RPC - TCP 53211" `
-Direction Inbound -Protocol TCP -LocalPort 53211 `
-RemoteAddress 10.20.0.0/16 -Action Allow -Profile Domain
New-NetFirewallRule `
-DisplayName "RPC Endpoint Mapper - TCP 135 from DCs" `
-Direction Inbound -Protocol TCP -LocalPort 135 `
-RemoteAddress 10.20.0.0/16 -Action Allow -Profile Domain
Do not expose these ports broadly. Other traffic may still be required depending on your topology:
| Function | Typical ports |
|---|---|
| DNS | TCP/UDP 53 |
| Kerberos | TCP/UDP 88 |
| LDAP | TCP/UDP 389 |
| SMB | TCP 445 |
| Global Catalog | TCP 3268 (or 3269 with SSL) |
| LDAP over SSL | TCP 636 |
| AD Web Services | TCP 9389 |
These are scenario-dependent; consult Microsoft’s current port guidance.
Netlogon needs a different port
The NTDS value controls the DRS interface only. If secure-channel, logon, or related Netlogon RPC traffic must cross the same restricted boundary, configure Netlogon separately under HKLMSYSTEMCurrentControlSetServicesNetlogonParameters using a different port:
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minutereg add "HKLMSYSTEMCurrentControlSetServicesNetlogonParameters" ^
/v DCTcpipPort /t REG_DWORD /d 53212 /f
net stop netlogon
net start netlogon
Open TCP 53212 as well. Never assign Netlogon’s DCTcpipPort the NTDS port; Microsoft documents a port conflict and Netlogon event 5809 in that case. A 5809 event during a service restart can also occur with a unique port; verify the final listener and connectivity before treating it as fatal. Configuring Netlogon alone is not a substitute for configuring NTDS, because clients and DCs use additional DRS, SAM, and LSA interfaces.
Rank #3
- GIGABIT ETHERNET PORTS: Features 5 x 1.0Gbps Ethernet ports for high-speed connectivity. Auto-negotiating ports detect the optimal speed for connected devices and work with existing Cat5e or Cat6 Ethernet cables.
- EASY SMART MANAGED NETWORK SWITCH: Intuitive software interface offers Easy Smart Managed Essentials capabilities to configure VLANs, prioritize traffic with QoS, monitor ports, and manage network security for small businesses.
- FLEXIBLE MOUNTING OPTIONS: Compact metal design supports desktop or wall-mount placement for versatile installation.
- SILENT & ENERGY-EFFICIENT OPERATION: Fanless design ensures silent performance, while IEEE 802.3az Energy Efficient Ethernet reduces power consumption without compromising high-speed network performance.
- REGIONAL COMPATIBILITY: Made for use in U.S. & CA only
SYSVOL is separate
AD DS replication and SYSVOL replication are different mechanisms. Current domains normally use DFSR; older environments may still use legacy FRS. A static NTDS port does not configure either one. Determine which technology your forest uses and configure its communication separately when it crosses the firewall. Test SYSVOL health independently: successful DRS replication does not prove that policies and scripts are replicating.
Verify registration and replication
1. Check the registry and listener
Get-ItemProperty `
-Path "HKLM:SYSTEMCurrentControlSetServicesNTDSParameters" `
-Name "TCP/IP Port"
Get-NetTCPConnection -LocalPort 53211 -State Listen
# or
netstat -ano | findstr ":53211"
A listening socket is only a first check; it does not by itself prove that the DRS interface registered correctly.
2. Query the Endpoint Mapper
From another DC, install/use Microsoft’s PortQry and run:
Recommended Free Tools
portqry -n dc02.example.com -p tcp -e 135
portqry -n dc02.example.com -e 53211
The TCP 135 query should list the MS NT Directory DRS Interface and its ncacn_ip_tcp endpoint. Its UUID is e3514235-4b06-11d1-ab04-00c04fc2dcd2. PortQry reports the direct test as LISTENING, FILTERED, or NOT LISTENING; use the result to distinguish firewall, routing, and service problems. PortQry documentation is available from Microsoft Learn.
Rank #4
- 24-Gigabit ports provide instant large file transfers
- 9K Jumbo frame improves performance of large data transfers
- Effective network monitoring via Port Mirroring, Loop Prevention and Cable Diagnostics
- Abundant VLAN features improve network security via traffic segmentation
- IGMP Snooping optimizes multicast applications
3. Force and inspect replication
repadmin /syncall dc01.example.com /AdeP
repadmin /showrepl dc01.example.com
repadmin /replsummary
Also inspect Directory Service, System, DFS Replication, and Netlogon logs, and verify forward and reverse DNS resolution from both DCs.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshooting
RPC error 1722: RPC server unavailable
Check TCP 135, the static port, host and network firewalls, routing, and whether the DC name resolves to the correct current address. A firewall may allow 135 while blocking the returned DRS endpoint. Microsoft’s 1722 guidance recommends testing both endpoint discovery and the service port.
RPC error 1753: no more endpoints available
TCP 135 may be reachable while the DRS endpoint is absent. Confirm the destination DC was restarted, the value is exactly TCP/IP Port under the NTDS key, the port is available, and PortQry lists the DRS UUID. See Microsoft’s 1753 guidance.
The port is not listening or a dynamic port appears
Recheck the key path and spelling, confirm decimal data, restart the DC, and ensure you are examining the DRS interface—not an unrelated RPC service. Do not infer DRS behavior merely from any high-numbered listener.
Best Value
- 16 10/100/1000Mbps RJ45 Ports
- Plug and play, with No configuration required
- Durable metal casing of superior quality and Professional appearance
- Intelligent management via a web user interface and downloadable Utility
- Green technology reduces power consumption
Replication works but logons fail
Open and test the separate Netlogon/LSA/SAM requirements, plus DNS, Kerberos, LDAP, SMB, and Global Catalog paths. Restricting NTDS alone does not make all domain-controller communication single-port.
SYSVOL does not update
Identify DFSR versus FRS and troubleshoot its service and firewall path independently.
Alternatives and trade-offs
- Static NTDS port: predictable and narrower than unrestricted dynamic RPC, but requires registry changes, restarts, port management, and additional rules for other services.
- Default dynamic RPC: operationally simpler, but modern Windows Server commonly uses TCP/UDP 49152–65535; legacy systems may use different ranges. Exposing that range is less attractive across tightly segmented networks.
- Custom restricted RPC range: useful when several RPC interfaces must traverse the firewall, but broader than one DRS endpoint and requiring compatibility testing.
- Firewall or VPN redesign: can simplify rule administration, but does not remove AD’s protocol dependencies or make replication automatically single-port.
Roll out gradually: document the port, configure one DC pair, restart and verify endpoint registration, force replication, then expand to the remaining DCs. Remove broad dynamic-RPC access only after all required AD, Netlogon, and SYSVOL paths have passed testing.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

