Article ID: 314976 - Last Review: October 30, 2006 - Revision: 2.2 How To Use the Ntdsutil Utility to Deny Access to IP Addresses in Windows 2000This article was previously published under Q314976 On This PageSUMMARY
This step-by-step article describes how to use the Ntdsutil utility to add an IP address to the IP Deny list. To provide higher levels of security for the domain controller, you can apply an IP Deny List that prevents the domain controller from accepting Lightweight Directory Access Protocol (LDAP) queries from clients that have specific IP addresses. The IP Deny List is similar to LDAP administration limits; it only alters the Default LDAP Policy object. The default LDAP policy is applied to any domain controller that has not had a specific LDAP policy applied to it or to the site in which it belongs. NOTE: To perform the procedure described in this article, you must be member of the Administrators group on a system that is running Windows 2000 Server or Windows 2000 Advanced Server. Ntdsutil is located in the Support tools folder on the Windows 2000 installation CD-ROM. How to Start Ntdsutil
How to Add an IP Address to the Deny List
How to Verify the Addition
REFERENCESFor additional information about how to automate procedures in Ntdsutil, click the article number below
to view the article in the Microsoft Knowledge Base:
243267
(http://support.microsoft.com/kb/243267/EN-US/
)
How to Automate Ntdsutil.exe Using a Script
| Article Translations
|

Back to the top
