we are deploying an AD into a VLANed network and that is our only AD. the AD is in the network of 192.168.10.0/28 and my workstations are in the network of 192.168.20.0/26. For the access list rule between both networks, what are the ports i have to enable (or port redirect) for the communication of AD and workstations, since i have blocked all the ports from my AD side for security reasons.