I can't say for sure what the problem is, but the best advice I can give is to LOG all traffic to that server that is not on those ports. You may see a very blatant pattern about what you aren't sending through. PS: you also need udp/tcp 53 DNS, or active directory gets fcked up. Maybe even WINS (tcp 42) is good if you have some legacy stuff.