Koldov Posted December 12, 2016 Posted December 12, 2016 Hi All, Does anybody have a quick list they could share? I am having trouble with SOLUS 3 communicating with the agent on a VM using NAT (target machine actively refused it). I have read it is possible to allow port forwarding to the VM and have a support case open with VMware, but I'm sure this is what he's going to ask me to do - so I'd like to have a list of the ports used at hand! Thanks in advance.
JATSO Posted December 12, 2016 Posted December 12, 2016 (edited) Hi All, Does anybody have a quick list they could share? I am having trouble with SOLUS 3 communicating with the agent on a VM using NAT (target machine actively refused it). I have read it is possible to allow port forwarding to the VM and have a support case open with VMware, but I'm sure this is what he's going to ask me to do - so I'd like to have a list of the ports used at hand! Thanks in advance. This is what i use: 52965:TCP:*:Enabled:SOLUS 3 Deployment Server 52966:TCP:*:Enabled:SOLUS 3 Agent 8739:TCP:*:Enabled:SOLUS 3 Agent Notifier UI Also, these ports need to be open on all devices: TCP 139, UDP 137, UPD 138 for browsing the network (NetBios) on all devices Edited December 12, 2016 by JATSO 1
Koldov Posted December 14, 2016 Author Posted December 14, 2016 (edited) Ok, so I've tried to give these ports out via GPO to a Windows 7 test machine. I used a slightly more thorough walk through: https://support.keystonemis.co.uk/hc/en-us/articles/211759183-Firewall-Exceptions It seemed to be practically the same as most of the other info, so I ran with it. I deliberately dropped the '*' wildcard for accepting connections and put in the SIMS server I.P. I also opened the NetBIOS ports within the same part of the GPO as the main ones in step 5. After a gpupdate /force, the test machine was visible from SOLUS and installed the AGENT and SIMS but asked for confirmation of allowing SOLUS 3 through the firewall... Unfortunately I allowed it without thinking, but it therefore seemed to me that there must be another Firewall entry I missed. It has appended 2 entries into the firewall rules (sims.solus3.agent.ui.exe) and these do not appear to have come from the GPO as they do not have a warning about being set by the administrator. Any ideas what I might of missed? Edit: What I have just noticed is that at the top of the picture is a program exception that was put into the GPO (C:\Windows\System32\wbem\unsecapp.exe:Enabled:.NET Proxy for DCOM (WMI).) in step 14 appears to be blocked...? Edited December 14, 2016 by Koldov
Koldov Posted December 15, 2016 Author Posted December 15, 2016 (edited) Ok, so tried on another machine and got the prompt asking me to give firewall access to SOLUS... This time I said no! Resulting in SOLUS giving an 'agent didn't respond / couldn't be contacted' message. Applied my GP (which I have now added port TCP135 for WMI to, as noted in another thread) and the agent responded. The .NET Proxy for DCOM (WMI) entry on this machine has been set on the firewall to ALLOW by the GPO, as it has now been for the initial test machine (not sure what happened there). The program entry in the firewall that is now blocked due to me clicking no on the prompt is - C:\program files\solus3\agentservice\sims.solus3.agent.ui.exe However, the agent still responds. So my question still remains the same. Why is SOLUS requesting firewall access on its own, is there something I have missed in the GP? Next is to try a machine with GP applied and then turn on the firewall... Edited December 15, 2016 by Koldov
Steve21 Posted December 15, 2016 Posted December 15, 2016 Which ones do you have one? Exception - C:\Windows\System32\wbem\unsecapp.exe:*:Enabled:.NET Proxy Direct Rule - 52965:TCP:*:enabled:SOLUS 3 Deployment Service Direct Rule - 52966:TCP:*:enabled:SOLUS 3 Agent Direct Rule - 135:TCP:*:enabled:WMI Direct Rule - 8739:TCP:*:enabled:SOLUS 3 Agent UI And then all the standard ones for File Sharing / Windows Remote Management etc? Steve
Koldov Posted December 15, 2016 Author Posted December 15, 2016 Yes, ll those mentioned there, plus file and printer sharing. Interestingly, 'Windows Firewall: Allow inbound file and printer sharing exception' states: Allows inbound file and printer sharing. To do this, Windows Firewall opens UDP ports 137 and 138, and TCP ports 139 and 445. So I may have doubled up opening them explicitly... I've just tested applying the GP to the computer and then turning on the firewall - no complaints from the SOLUS agent and responding to check from server! The firewall has put an exception in (but blocked) for - C:\program files\solus3\agentservice\sims.solus3.agent.ui.exe - in the 'Public Network' profile, but nothing in Domain. So it appears the GP has that program covered somehow, but must be applied before the firewall is turned on (which I guess makes sense really). Windows Firewall: Allow inbound file and printer sharing exception (from XX.X.XXX.X) Windows Firewall: Allow inbound remote administration exception (from XX.X.XXX.X) Windows Firewall: Define inbound port exceptions: 52965:TCP:XX.X.XXX.X:Enabled:SOLUS 3 Deployment Server 52966:TCP:XX.X.XXX.X:Enabled:SOLUS 3 Agent 8739:TCP:XX.X.XXX.X:Enabled:SOLUS 3 Agent Notifier UI 137:UDP:XX.X.XXX.X:Enabled:SOLUS 3 NetBios 138:UDP:XX.X.XXX.X:Enabled:SOLUS 3 NetBios 139:TCP:XX.X.XXX.X:Enabled:SOLUS 3 NetBios 135:TCP:XX.X.XXX.X:Enabled:WMI Windows Firewall: Define inbound program exceptions - C:\Windows\System32\wbem\unsecapp.exe:XX.X.XXX.X:Enabled:.NET Proxy for DCOM (WMI) Note: There are no wildcards - SIMS/SOLUS server explicitly defined in all entries
Koldov Posted December 15, 2016 Author Posted December 15, 2016 Wow! How frustrating! This pops up after a reboot...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now