Active directory ports required. Deploy domain controllers in private subnets.