Jump to content

Recommended Posts

Posted

If I turn off the firewall the client will install successfully. I have opened the following ports via GP and tested the policy is applying:

sccmports.PNG

What have I missed that is blocking this?

Posted
If I turn off the firewall the client will install successfully. I have opened the following ports via GP and tested the policy is applying:

[ATTACH=CONFIG]15055[/ATTACH]

What have I missed that is blocking this?

 

On the workstation enable Windows Management Instrumentation WMI program.

 

I've tried this by just opening the ports by policy and it didn't work.

 

Alternatively you can do this by machine policy on a 2008 R2 Server

 

Goto Computer Configuration > Policies > Windows Settings > Security Settings > Windows Firewall with Advanced Security > Inbound Rules

 

Select a Predifined Rule for WMI in Rule Type.

 

Should do the trick

Posted

I actually forgot to do it in the image and done it through policy without a problem.

 

Can you connect any other service via WMI (i.e. VAMT) to jus check and make sure the port is open on the laptop.

 

From memory I also think you need to make Domain Admins a member of the administrators group on the local PC for SCCM client to install.

Posted
Try adding the SCCM server's computer account to the local administrators group (try by hand first to make sure it works, then can be done through group policy). Seemed to do the trick for me.
  • Thanks 1
  • 1 month later...
Posted

right still struggling to get the client to push out from SCCM so Im going to look at using just group policy

 

Ive imported the ADM files for it but not sure what settings need to be configured?

  • 3 months later...
  • 4 weeks later...
Posted

Nope. Still having the same problem. The only way I seem to be able to get it to work is to move computers account in AD to the default Computers container, and then manually tun off the firewall on the device.

 

If I move the computer account to another container, which has a group policy to explicitely disable all windows firewall, the client fails to install.

 

Using CMTRACE I can see the folliwing:

 

What might I have done wrong?

 

Anyone?

 

smsclientfail.PNG

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...