Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Yes. On supported Windows Server domain controllers, assign the AD DS (DRS) RPC endpoint a fixed TCP port by creating the TCP/IP Port DWORD under HKLMSYSTEMCurrentControlSetServicesNTDSParameters. Restart each participating domain controller, then permit TCP 135 (the RPC Endpoint Mapper) and the selected static port. For example, using TCP 53211 means allowing both 135 and 53211 between the relevant domain controllers. A single NTDS port does not cover Netlogon, SYSVOL replication, DNS, Kerberos, LDAP, SMB, or other domain-controller traffic.

How the connection works

AD DS replication uses Microsoft RPC. The source DC first contacts the destination DC’s RPC Endpoint Mapper on TCP 135. The mapper returns the port registered by the Directory Replication Service (DRS) interface; replication payloads then use that endpoint.

Source DC --TCP 135--> Destination DC (RPC Endpoint Mapper)
Source DC --TCP 53211--> Destination DC (NTDS/DRS)

Therefore, the instruction “set a static port and block 135” is incorrect. Blocking 135 prevents endpoint discovery and commonly causes RPC errors 1722 or 1753. See Microsoft’s static AD RPC guidance and domain-controller firewall matrix.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Plan the change

  • Apply the setting to every DC that must communicate across the restricted firewall path. Replication is bidirectional and topology-dependent.
  • Choose an unused, documented TCP port approved by your organization. Microsoft does not mandate a universal number; 53211 is only an example.
  • Check local listeners and service assignments on every DC. Do not reuse the port for Netlogon.
  • Confirm routing, DNS resolution, firewall ownership, and a restart/change window.
  • Decide whether Netlogon, DFSR/FRS, or client RPC traffic also crosses the boundary; those services require separate planning.

Configure a static NTDS replication port

Registry Editor

  1. Sign in to the domain controller with administrative rights and open Registry Editor.
  2. Go to HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesNTDSParameters.
  3. Create or edit a DWORD (32-bit) Value named TCP/IP Port.
  4. Choose Decimal and enter the selected port, such as 53211.
  5. Restart the computer. The NTDS service must restart before the value takes effect.

Back up the registry and use normal change control; an incorrect registry edit can make a server or service unusable.

#1 Best Overall
Sale
NETGEAR 8-Port Gigabit Ethernet Easy Smart Managed Network Switch (GS308E)
  • PLUG-AND-PLAY GIGABIT MANAGED SWITCH: 8 x 1Gbps auto-negotiating ports work the moment you plug in — full-gigabit speed over Cat5e/Cat6 cabling.
  • MANAGED, WITHOUT THE COMPLEXITY: Easy Smart web GUI on Windows, Mac or Linux — no app or Windows-only utility, unlike many competing switches.
  • SEGMENT & PRIORITIZE TRAFFIC: Up to 64 VLANs, QoS, IGMP snooping and port mirroring keep voice, video and data fast, secure and organized.
  • BUILT-IN PROTECTION: Auto DoS prevention, loop detection, broadcast storm control and cable test keep your network stable and easy to troubleshoot.
  • RELIABLE 24/7 BACKBONE: Rugged fanless metal housing runs cool and silent at 0 dBA — the managed switch trusted in homes, offices and small business.

Command line

reg add "HKLMSYSTEMCurrentControlSetServicesNTDSParameters" ^
  /v "TCP/IP Port" /t REG_DWORD /d 53211 /f
shutdown /r /t 0

Repeat the configuration on each applicable DC, changing the value only if your design deliberately assigns different destination ports and matching firewall rules. A consistent port simplifies operations.

Allow the required firewall paths

For the example above, permit the relevant DC addresses or subnets—not the entire network—to reach:

Port Purpose
TCP 135 RPC Endpoint Mapper
TCP 53211 Static NTDS/DRS replication endpoint

Replication initiations can occur in either direction, so site firewalls and host firewalls normally need reciprocal DC-to-DC rules. Check network ACLs, VPN/security appliances, Windows Defender Firewall, and endpoint-security products.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Example inbound Windows Defender Firewall rules (replace the addresses with approved DC IPs or subnets):

Rank #2
TP-Link 8 Port Gigabit Switch | Easy Smart Managed | Plug & Play | Desktop/Wall-Mount | Sturdy Metal w/ Shielded Ports | Support QoS, Vlan, IGMP and LAG (TL-SG108E)
  • 8 Gigabit Ethernet Ports: Expand your network with 8 high-speed ethernet ports for enhanced connectivity and performance
  • Easy Smart Management: Manage and configure your network effortlessly via a web interface or free software
  • Support VLAN: Segment traffic with up to 32 VLANs simultaneously out of 4K VLAN IDs for better security
  • Network Monitoring: Monitor your network effectively with port mirroring, loop prevention, and cable diagnostics
  • IGMP Snooping: Enhances multicast application performance for improved network efficiency
New-NetFirewallRule `
  -DisplayName "AD DS Replication RPC - TCP 53211" `
  -Direction Inbound -Protocol TCP -LocalPort 53211 `
  -RemoteAddress 10.20.0.0/16 -Action Allow -Profile Domain

New-NetFirewallRule `
  -DisplayName "RPC Endpoint Mapper - TCP 135 from DCs" `
  -Direction Inbound -Protocol TCP -LocalPort 135 `
  -RemoteAddress 10.20.0.0/16 -Action Allow -Profile Domain

Do not expose these ports broadly. Other traffic may still be required depending on your topology:

Function Typical ports
DNS TCP/UDP 53
Kerberos TCP/UDP 88
LDAP TCP/UDP 389
SMB TCP 445
Global Catalog TCP 3268 (or 3269 with SSL)
LDAP over SSL TCP 636
AD Web Services TCP 9389

These are scenario-dependent; consult Microsoft’s current port guidance.

Netlogon needs a different port

The NTDS value controls the DRS interface only. If secure-channel, logon, or related Netlogon RPC traffic must cross the same restricted boundary, configure Netlogon separately under HKLMSYSTEMCurrentControlSetServicesNetlogonParameters using a different port:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
reg add "HKLMSYSTEMCurrentControlSetServicesNetlogonParameters" ^
  /v DCTcpipPort /t REG_DWORD /d 53212 /f
net stop netlogon
net start netlogon

Open TCP 53212 as well. Never assign Netlogon’s DCTcpipPort the NTDS port; Microsoft documents a port conflict and Netlogon event 5809 in that case. A 5809 event during a service restart can also occur with a unique port; verify the final listener and connectivity before treating it as fatal. Configuring Netlogon alone is not a substitute for configuring NTDS, because clients and DCs use additional DRS, SAM, and LSA interfaces.

Rank #3
Sale
NETGEAR 5-Port Gigabit Ethernet Easy Smart Managed Network Switch (GS305E)
  • GIGABIT ETHERNET PORTS: Features 5 x 1.0Gbps Ethernet ports for high-speed connectivity. Auto-negotiating ports detect the optimal speed for connected devices and work with existing Cat5e or Cat6 Ethernet cables.
  • EASY SMART MANAGED NETWORK SWITCH: Intuitive software interface offers Easy Smart Managed Essentials capabilities to configure VLANs, prioritize traffic with QoS, monitor ports, and manage network security for small businesses.
  • FLEXIBLE MOUNTING OPTIONS: Compact metal design supports desktop or wall-mount placement for versatile installation.
  • SILENT & ENERGY-EFFICIENT OPERATION: Fanless design ensures silent performance, while IEEE 802.3az Energy Efficient Ethernet reduces power consumption without compromising high-speed network performance.
  • REGIONAL COMPATIBILITY: Made for use in U.S. & CA only

SYSVOL is separate

AD DS replication and SYSVOL replication are different mechanisms. Current domains normally use DFSR; older environments may still use legacy FRS. A static NTDS port does not configure either one. Determine which technology your forest uses and configure its communication separately when it crosses the firewall. Test SYSVOL health independently: successful DRS replication does not prove that policies and scripts are replicating.

Verify registration and replication

1. Check the registry and listener

Get-ItemProperty `
  -Path "HKLM:SYSTEMCurrentControlSetServicesNTDSParameters" `
  -Name "TCP/IP Port"

Get-NetTCPConnection -LocalPort 53211 -State Listen
# or
netstat -ano | findstr ":53211"

A listening socket is only a first check; it does not by itself prove that the DRS interface registered correctly.

2. Query the Endpoint Mapper

From another DC, install/use Microsoft’s PortQry and run:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
portqry -n dc02.example.com -p tcp -e 135
portqry -n dc02.example.com -e 53211

The TCP 135 query should list the MS NT Directory DRS Interface and its ncacn_ip_tcp endpoint. Its UUID is e3514235-4b06-11d1-ab04-00c04fc2dcd2. PortQry reports the direct test as LISTENING, FILTERED, or NOT LISTENING; use the result to distinguish firewall, routing, and service problems. PortQry documentation is available from Microsoft Learn.

Rank #4
TP-Link TL-SG1024DE, 24 Port Gigabit Easy Smart Managed Ehternet Switch
  • 24-Gigabit ports provide instant large file transfers
  • 9K Jumbo frame improves performance of large data transfers
  • Effective network monitoring via Port Mirroring, Loop Prevention and Cable Diagnostics
  • Abundant VLAN features improve network security via traffic segmentation
  • IGMP Snooping optimizes multicast applications

3. Force and inspect replication

repadmin /syncall dc01.example.com /AdeP
repadmin /showrepl dc01.example.com
repadmin /replsummary

Also inspect Directory Service, System, DFS Replication, and Netlogon logs, and verify forward and reverse DNS resolution from both DCs.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting

RPC error 1722: RPC server unavailable

Check TCP 135, the static port, host and network firewalls, routing, and whether the DC name resolves to the correct current address. A firewall may allow 135 while blocking the returned DRS endpoint. Microsoft’s 1722 guidance recommends testing both endpoint discovery and the service port.

RPC error 1753: no more endpoints available

TCP 135 may be reachable while the DRS endpoint is absent. Confirm the destination DC was restarted, the value is exactly TCP/IP Port under the NTDS key, the port is available, and PortQry lists the DRS UUID. See Microsoft’s 1753 guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The port is not listening or a dynamic port appears

Recheck the key path and spelling, confirm decimal data, restart the DC, and ensure you are examining the DRS interface—not an unrelated RPC service. Do not infer DRS behavior merely from any high-numbered listener.

Best Value
Sale
TP-Link 16 Port Gigabit Switch | Easy Smart Managed | Plug & Play | Limited Lifetime Protection | Desktop/Wall-Mount | Sturdy Metal w/ Shielded Ports | Support QoS, Vlan, IGMP and LAG (TL-SG116E)
  • 16 10/100/1000Mbps RJ45 Ports
  • Plug and play, with No configuration required
  • Durable metal casing of superior quality and Professional appearance
  • Intelligent management via a web user interface and downloadable Utility
  • Green technology reduces power consumption

Replication works but logons fail

Open and test the separate Netlogon/LSA/SAM requirements, plus DNS, Kerberos, LDAP, SMB, and Global Catalog paths. Restricting NTDS alone does not make all domain-controller communication single-port.

SYSVOL does not update

Identify DFSR versus FRS and troubleshoot its service and firewall path independently.

Alternatives and trade-offs

  • Static NTDS port: predictable and narrower than unrestricted dynamic RPC, but requires registry changes, restarts, port management, and additional rules for other services.
  • Default dynamic RPC: operationally simpler, but modern Windows Server commonly uses TCP/UDP 49152–65535; legacy systems may use different ranges. Exposing that range is less attractive across tightly segmented networks.
  • Custom restricted RPC range: useful when several RPC interfaces must traverse the firewall, but broader than one DRS endpoint and requiring compatibility testing.
  • Firewall or VPN redesign: can simplify rule administration, but does not remove AD’s protocol dependencies or make replication automatically single-port.

Roll out gradually: document the port, configure one DC pair, restart and verify endpoint registration, force replication, then expand to the remaining DCs. Remove broad dynamic-RPC access only after all required AD, Netlogon, and SYSVOL paths have passed testing.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Bestseller No. 2
SaleBestseller No. 3
NETGEAR 5-Port Gigabit Ethernet Easy Smart Managed Network Switch (GS305E)
NETGEAR 5-Port Gigabit Ethernet Easy Smart Managed Network Switch (GS305E)
REGIONAL COMPATIBILITY: Made for use in U.S. & CA only
$21.99
Bestseller No. 4
TP-Link TL-SG1024DE, 24 Port Gigabit Easy Smart Managed Ehternet Switch
TP-Link TL-SG1024DE, 24 Port Gigabit Easy Smart Managed Ehternet Switch
24-Gigabit ports provide instant large file transfers; 9K Jumbo frame improves performance of large data transfers
$99.99
SaleBestseller No. 5
TP-Link 16 Port Gigabit Switch | Easy Smart Managed | Plug & Play | Limited Lifetime Protection | Desktop/Wall-Mount | Sturdy Metal w/ Shielded Ports | Support QoS, Vlan, IGMP and LAG (TL-SG116E)
TP-Link 16 Port Gigabit Switch | Easy Smart Managed | Plug & Play | Limited Lifetime Protection | Desktop/Wall-Mount | Sturdy Metal w/ Shielded Ports | Support QoS, Vlan, IGMP and LAG (TL-SG116E)
16 10/100/1000Mbps RJ45 Ports; Plug and play, with No configuration required; Durable metal casing of superior quality and Professional appearance
$59.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.