Jump to content

Recommended Posts

Posted

Hi All,

 

Does anybody have a quick list they could share?

 

I am having trouble with SOLUS 3 communicating with the agent on a VM using NAT (target machine actively refused it).

 

I have read it is possible to allow port forwarding to the VM and have a support case open with VMware, but I'm sure this is what he's going to ask me to do - so I'd like to have a list of the ports used at hand!

 

Thanks in advance.

Posted (edited)
Hi All,

 

Does anybody have a quick list they could share?

 

I am having trouble with SOLUS 3 communicating with the agent on a VM using NAT (target machine actively refused it).

 

I have read it is possible to allow port forwarding to the VM and have a support case open with VMware, but I'm sure this is what he's going to ask me to do - so I'd like to have a list of the ports used at hand!

 

Thanks in advance.

 

This is what i use:

 

52965:TCP:*:Enabled:SOLUS 3 Deployment Server

52966:TCP:*:Enabled:SOLUS 3 Agent

8739:TCP:*:Enabled:SOLUS 3 Agent Notifier UI

 

Also, these ports need to be open on all devices: TCP 139, UDP 137, UPD 138 for browsing the network (NetBios) on all devices

Edited by JATSO
  • Thanks 1
Posted (edited)

Ok, so I've tried to give these ports out via GPO to a Windows 7 test machine.

 

I used a slightly more thorough walk through:

 

https://support.keystonemis.co.uk/hc/en-us/articles/211759183-Firewall-Exceptions

 

It seemed to be practically the same as most of the other info, so I ran with it.

 

I deliberately dropped the '*' wildcard for accepting connections and put in the SIMS server I.P.

 

I also opened the NetBIOS ports within the same part of the GPO as the main ones in step 5.

 

After a gpupdate /force, the test machine was visible from SOLUS and installed the AGENT and SIMS but asked for confirmation of allowing SOLUS 3 through the firewall...

 

Unfortunately I allowed it without thinking, but it therefore seemed to me that there must be another Firewall entry I missed.

 

It has appended 2 entries into the firewall rules (sims.solus3.agent.ui.exe) and these do not appear to have come from the GPO as they do not have a warning about being set by the administrator.

 

SOLUS vs FIREWALL.jpg

 

Any ideas what I might of missed?

 

Edit: What I have just noticed is that at the top of the picture is a program exception that was put into the GPO (C:\Windows\System32\wbem\unsecapp.exe:Enabled:.NET Proxy for DCOM (WMI).) in step 14 appears to be blocked...?

Edited by Koldov
Posted (edited)

Ok, so tried on another machine and got the prompt asking me to give firewall access to SOLUS...

 

This time I said no!

 

Resulting in SOLUS giving an 'agent didn't respond / couldn't be contacted' message.

 

Applied my GP (which I have now added port TCP135 for WMI to, as noted in another thread) and the agent responded.

 

The .NET Proxy for DCOM (WMI) entry on this machine has been set on the firewall to ALLOW by the GPO, as it has now been for the initial test machine (not sure what happened there).

 

The program entry in the firewall that is now blocked due to me clicking no on the prompt is - C:\program files\solus3\agentservice\sims.solus3.agent.ui.exe

 

SOLUS vs FIREWALL round 2.jpg

 

However, the agent still responds.

 

So my question still remains the same. Why is SOLUS requesting firewall access on its own, is there something I have missed in the GP?

 

Next is to try a machine with GP applied and then turn on the firewall...

Edited by Koldov
Posted

Which ones do you have one?

 

Exception - C:\Windows\System32\wbem\unsecapp.exe:*:Enabled:.NET Proxy

Direct Rule - 52965:TCP:*:enabled:SOLUS 3 Deployment Service

Direct Rule - 52966:TCP:*:enabled:SOLUS 3 Agent

Direct Rule - 135:TCP:*:enabled:WMI

Direct Rule - 8739:TCP:*:enabled:SOLUS 3 Agent UI

 

And then all the standard ones for File Sharing / Windows Remote Management etc?

 

Steve

Posted

Yes, ll those mentioned there, plus file and printer sharing.

 

Interestingly, 'Windows Firewall: Allow inbound file and printer sharing exception' states:

Allows inbound file and printer sharing. To do this, Windows Firewall opens UDP ports 137 and 138, and TCP ports 139 and 445.

 

So I may have doubled up opening them explicitly...

 

I've just tested applying the GP to the computer and then turning on the firewall - no complaints from the SOLUS agent and responding to check from server!

 

The firewall has put an exception in (but blocked) for - C:\program files\solus3\agentservice\sims.solus3.agent.ui.exe - in the 'Public Network' profile, but nothing in Domain.

 

So it appears the GP has that program covered somehow, but must be applied before the firewall is turned on (which I guess makes sense really).

 

Windows Firewall: Allow inbound file and printer sharing exception (from XX.X.XXX.X)

 

Windows Firewall: Allow inbound remote administration exception (from XX.X.XXX.X)

 

Windows Firewall: Define inbound port exceptions:

 

52965:TCP:XX.X.XXX.X:Enabled:SOLUS 3 Deployment Server

52966:TCP:XX.X.XXX.X:Enabled:SOLUS 3 Agent

8739:TCP:XX.X.XXX.X:Enabled:SOLUS 3 Agent Notifier UI

137:UDP:XX.X.XXX.X:Enabled:SOLUS 3 NetBios

138:UDP:XX.X.XXX.X:Enabled:SOLUS 3 NetBios

139:TCP:XX.X.XXX.X:Enabled:SOLUS 3 NetBios

135:TCP:XX.X.XXX.X:Enabled:WMI

 

Windows Firewall: Define inbound program exceptions - C:\Windows\System32\wbem\unsecapp.exe:XX.X.XXX.X:Enabled:.NET Proxy for DCOM (WMI)

 

Note: There are no wildcards - SIMS/SOLUS server explicitly defined in all entries

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...