Domain controller
LDAP (389/3268 TCP/UDP), Kerberos (88 TCP/UDP), DNS (53 TCP/UDP), RPC netlogon (135 TCP)
Exchange 2007 Hub Transport server
SMTP (25/587 TCP) SSL
Exchange 2007 Mailbox server
RPC MAPI (135 TCP)
SMTP Relay servers (in a perimeter network)
SMTP (25,995 SMTP TLS)
Exchange 2007 Unified Messaging server
SMTP (25,995 SMTP TLS)
Exchange 2007 Mailbox server
RPC MAPI (135 TCP), many dynamic*
Exchange 2007 Unified Messaging server
VoIP (TCP 5060,5061 SSL,5065,5066)
Public Folders (hosted by an Exchange 2007 Mailbox server)
RPC MAPI (135 TCP)
Public Folders (hosted by an Exchange 2007 Mailbox server)
RPC MAPI (135 TCP), many dynamic*
Exchange 2007 Client Access server
80/443 TCP SSL
Outlook 2003 client
RPC over HTTP (80/443 TCP)
Outlook 2007 client
RPC over HTTP (80/443 TCP)
Other clients (POP3/SMTP/IMAP4)
POP3 (110/995 TCP), IMAP (143/993 TCP), see too 995 SMTP TLS
/
* By default, "many dynamic ports" is the port range 1024-65535.
Understanding the Ports That Are Used by Exchange 2007 in a Mixed Environment
It may change, if setup RPC range port:
Setup RPC range port in server and clients workstation!
How to configure RPC dynamic port allocation to work with firewalls
Additional:
Restricting Active Directory replication traffic and client RPC traffic to a specific port
Configuring Domain Controller Ports Windows 2000/2003 Replication through a Firewall
To test were more meaningful use these wonderful free Architecture magazines and papers:
Microsoft Download Center: Architecture
Microsoft Download Center: Architecture diagrams
Microsoft Download Center: Architecture poster
Well, get some magically materials Microsoft Airlift.