Koldov Posted June 15, 2021 Posted June 15, 2021 Won't go into the who, what, when, where and why.... but the server doesn't have the firewall turned on... I turned it on... everybody lost their minds as they couldn't access SIMS! The teacher laptops and admin computers have the following GPO settings applied. But I can't see anything for the server, is it the same settings (or just some of them)? Computer Configuration (Enabled) Policies Administrative Templates Network/Network Connections/Windows Defender Firewall/Domain Profile Windows Defender Firewall: Allow inbound file and printer sharing exception - Enabled - Allow unsolicited messages from these IP addresses: xx.x.xxx.x (this is the server's IP) Windows Defender Firewall: Allow inbound remote administration exception - Enabled - Allow unsolicited messages from these IP addresses: xx.x.xxx.x (this is the server's IP) Windows Defender Firewall: Define inbound port exceptions - Enabled Define port exceptions: 52965:TCP:*:Enabled:SOLUS 3 Deployment Server 52966:TCP:*:Enabled:SOLUS 3 Agent 8739:TCP:*:Enabled:SOLUS 3 Agent Notifier UI 135:TCP:*:Enabled:WMI Windows Defender Firewall: Define inbound program exceptions - Enabled Define program exceptions: C:\Windows\System32\wbem\unsecapp.exe:*:Enabled:.NET Proxy for DCOM (WMI) C:\program files\solus3\agentservice\sims.solus3.agent.ui.exe:*:Enabled:Sims.Solus3.Agent.UI
Boredguy Posted June 15, 2021 Posted June 15, 2021 Don't forget you need to make sure that the SQL server is allowed to have traffic in and out of the firewall, as the exceptions above are purely for Solus3 We have 8080 allowed for the DocumentStore and 49295 for the SQL (both TCP) 1
Koldov Posted June 15, 2021 Author Posted June 15, 2021 I found SIMS DOCS in the 'Inbound Rules' but nothing for outbound...? I added SQL SERVER to the list of 'Inbound Rules' as well, I gave it ALL the ports as I couldn't find out how to tell which one it's using and I did it through the Wizard so it gave itself TCP/UDP too. So I don't need to add the rules in the OP to the server firewall? The first two relate to the server's own IP and the rest are all relating to inbound connections from SOLUS on the server...?
Boredguy Posted June 15, 2021 Posted June 15, 2021 The ones in your OP are needed to allow Solus to communicate with the clients (and vice versa), the SQL/Docstorage ones are needed for SIMS.net to function
jthompson Posted June 15, 2021 Posted June 15, 2021 (edited) I added SQL SERVER to the list of 'Inbound Rules' as well, I gave it ALL the ports as I couldn't find out how to tell which one it's using and I did it through the Wizard so it gave itself TCP/UDP too. Depending on your SQL Server config, you might need to have the SQL Server Browser service running in order for clients to connect to SQL Server. On your server, in SQL Server Configuration Manager > SQL Server Network Configuration > Protocols > TCP/IP > IP Addresses > IPAll you will be able to see whether dynamic ports are in use (SQL Server Browser service will be needed), and if not, which TCP port SQL Server is set to use. If you've got a static port set, that should help you limit the corresponding firewall rule so that you're not leaving all ports open. Edit: You might need the service running regardless, thinking about it. Edited June 15, 2021 by jthompson 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now