Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Won't go into the who, what, when, where and why.... but the server doesn't have the firewall turned on...

 

I turned it on... everybody lost their minds as they couldn't access SIMS!

 

The teacher laptops and admin computers have the following GPO settings applied.

 

But I can't see anything for the server, is it the same settings (or just some of them)?

 

Computer Configuration (Enabled)

 

Policies

 

Administrative Templates

 

Network/Network Connections/Windows Defender Firewall/Domain Profile

 

Windows Defender Firewall: Allow inbound file and printer sharing exception - Enabled - Allow unsolicited messages from these IP addresses: xx.x.xxx.x (this is the server's IP)

 

Windows Defender Firewall: Allow inbound remote administration exception - Enabled - Allow unsolicited messages from these IP addresses: xx.x.xxx.x (this is the server's IP)

 

Windows Defender Firewall: Define inbound port exceptions - Enabled

Define port exceptions:

52965:TCP:*:Enabled:SOLUS 3 Deployment Server

52966:TCP:*:Enabled:SOLUS 3 Agent

8739:TCP:*:Enabled:SOLUS 3 Agent Notifier UI

135:TCP:*:Enabled:WMI

 

Windows Defender Firewall: Define inbound program exceptions - Enabled

Define program exceptions:

C:\Windows\System32\wbem\unsecapp.exe:*:Enabled:.NET Proxy for DCOM (WMI)

C:\program files\solus3\agentservice\sims.solus3.agent.ui.exe:*:Enabled:Sims.Solus3.Agent.UI

Posted

Don't forget you need to make sure that the SQL server is allowed to have traffic in and out of the firewall, as the exceptions above are purely for Solus3

 

We have 8080 allowed for the DocumentStore and 49295 for the SQL (both TCP)

  • Thanks 1
Posted

I found SIMS DOCS in the 'Inbound Rules' but nothing for outbound...?

 

SIMS DOC STORE.JPG

 

I added SQL SERVER to the list of 'Inbound Rules' as well, I gave it ALL the ports as I couldn't find out how to tell which one it's using and I did it through the Wizard so it gave itself TCP/UDP too.

 

So I don't need to add the rules in the OP to the server firewall? The first two relate to the server's own IP and the rest are all relating to inbound connections from SOLUS on the server...?

Posted
The ones in your OP are needed to allow Solus to communicate with the clients (and vice versa), the SQL/Docstorage ones are needed for SIMS.net to function
Posted (edited)
I added SQL SERVER to the list of 'Inbound Rules' as well, I gave it ALL the ports as I couldn't find out how to tell which one it's using and I did it through the Wizard so it gave itself TCP/UDP too.

 

Depending on your SQL Server config, you might need to have the SQL Server Browser service running in order for clients to connect to SQL Server.

 

On your server, in SQL Server Configuration Manager > SQL Server Network Configuration > Protocols > TCP/IP > IP Addresses > IPAll you will be able to see whether dynamic ports are in use (SQL Server Browser service will be needed), and if not, which TCP port SQL Server is set to use. If you've got a static port set, that should help you limit the corresponding firewall rule so that you're not leaving all ports open.

 

Edit: You might need the service running regardless, thinking about it.

Edited by jthompson
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...