Jump to content

Recommended Posts

Posted

So over half term we got LEA to move our SIMS from a desktop pc to a dedicated Server. They installed SIMS moved the database and got everything working.

We have 6 PC's that use SIMS they are stand alone computers and not controlled by AD or anything like that.

Forgive me as I no very little about SIMS, I tend to keep away from it as we have proper support contract for it.

However we have been told about SOLUS 3, is needed for updates. I got a list or ports

Notes

What firewall exceptions does SOLUS 3 require to be input in Windows Firewall

 

Configuring the Windows Firewall for SOLUS³ Agent Communication

Workaround

1. Load the Group Policy Editor and navigate to the Windows Firewall node (http://technet.microsoft.com/en-us/library/bb490626.aspx).

2. Open the Windows Firewall: Define port exceptions properties dialog.

 

IMPORTANT NOTE: Ensure that you access the Windows Firewall: Define port exceptions properties via the correct route. The correct route is Computer Configuration | Policies | Administrative Templates | Network | Network Connections | Windows Firewall | Domain Profile | Windows Firewall: Define inbound port exceptions.

 

3. Select the Enabled radio button.

4. In the Options panel, click the Show button to display the Show Contents dialog.

5. Add the following values:

52965:TCP:*:Enabled:SOLUS 3 Deployment Server

52966:TCP:*:Enabled:SOLUS 3 Agent

8739:TCP:*:Enabled:SOLUS 3 Agent Notifier UI

IMPORTANT NOTE: Setting group policy port exceptions disables local port exceptions unless overridden in group policy. To do this, open the Windows Firewall: Allow local port exceptions properties dialog and select the Enabled radio button.

 

6. Click the OK button to close the Show Contents dialog.

7. Click the OK button to close the Windows Firewall: Define inbound port exceptions dialog.

8. Open the Windows Firewall: Allow inbound remote administration exception properties dialog.

 

IMPORTANT NOTE: Ensure that you access the Windows Firewall: Allow inbound remote administration exception properties via the correct route. The correct route is Computer Configuration | Policies | Administrative Templates | Network | Network Connections | Windows Firewall | Domain Profile | Windows Firewall: Allow inbound remote administration exception.

 

9. Select the Enabled radio button.

10. In the Options panel, enter * in the Allow unsolicited incoming messages from these IP addresses: field.

11. Click the OK button to close the Windows Firewall: Allow inbound remote administration exception dialog.

12. Open the Windows Firewall: Define inbound program exceptions dialog.

13. In the Options panel, click the Show button to display the Show Contents dialog.

14. Enter: C:\Windows\System32\wbem\unsecapp.exe:Enabled:*:.NET Proxy for DCOM (WMI).

15. Click the OK button to close the Windows Firewall: Define inbound program exceptions dialog.

 

Also, these ports need to be open on all devices: TCP 139, UDP 137, UPD 138 for browsing the network (NetBios) on all devices.

Is the but in red above needed as with out it it looks like that is blocked on the firewall

I have done this on the server and the PC's. But when we are on the server and try adding an agent we get an install failed error ( Access denied to remote machine ) Tried the two different admin passwords for the pc's at a loss as to what it could be.

We use Avast Business as Antivirus.

The guy tried telnetting to the pc and that didnt work either.

 

Any ideas?

  • Thanks 1
Posted (edited)
File and Printer sharing exception > Enabled for *

Prohibit Notification > Enabled

Allow remote administration exception > Enabled for *

Define Port Exceptions > Enabled - Show - Add -

 

52965:TCP:*:enabled:SOLUS 3 Deployment service

52966:TCP:*:enabled:SOLUS 3 Agent

135:TCP:*:enabled:WMI

8739:TCP:*:enabled:SOLUS 3 Agent UI

 

Is all we ever used at any of our places for Solus 3 in the past (Haven't used it recently if it might have changed)

 

And the admin password is the domain admin one we normally use when deploying to a machine

 

Steve

Edited by Steve21
  • Thanks 1
  • 1 year later...
Posted
Could it be the network profile in use on the clients? The instructions provided by Capita for setting up Windows firewall exceptions for SOLUS 3 put the settings under the Domain profile. Have a look at Windows firewall on your clients and see which profile is active, and set up the SOLUS 3 exceptions under that profile.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...