Hello,
I mean a hardware firewall (checkpoint), not the windows firewall. The windows firewall is disabled.
On our hardware firewall I don't see any drops. I see only traffic to port 135, and not on the dynamic dcom port.
I have configured the port according to http://support.microsoft.com/kb/154596
workstations outside the firewall can be managed with the same settings.