Hello, we are implementing a new Exchange 2013 deployment and our environment is such that we have 2 hubs (one main hub and one for disaster recovery) and 50 branch locations. Each branch location has 2 domain controllers (for redundancy and all have global
catalog). I have noticed that the CAS role servers for Exchange 2013 have been making LDAP and GC queries to all of the domain controllers everywhere but our firewalls are blocking the traffic. Everything seems to work fine so far but I was wondering if it
is recommended or necessary to allow LDAP and GC ports from the Exchange CAS's to every DC/GC in our organization. The CAS's do currently have full communication with some of our DC/GC's including the FSMO role holders.
Thank you in advance for your time!