RabbieBurns Posted September 4, 2012 Posted September 4, 2012 If I turn off the firewall the client will install successfully. I have opened the following ports via GP and tested the policy is applying: What have I missed that is blocking this?
Davit2005 Posted September 4, 2012 Posted September 4, 2012 If I turn off the firewall the client will install successfully. I have opened the following ports via GP and tested the policy is applying: [ATTACH=CONFIG]15055[/ATTACH] What have I missed that is blocking this? On the workstation enable Windows Management Instrumentation WMI program. I've tried this by just opening the ports by policy and it didn't work. Alternatively you can do this by machine policy on a 2008 R2 Server Goto Computer Configuration > Policies > Windows Settings > Security Settings > Windows Firewall with Advanced Security > Inbound Rules Select a Predifined Rule for WMI in Rule Type. Should do the trick
RabbieBurns Posted September 4, 2012 Author Posted September 4, 2012 i tried enabling WMI manually on a couple of laptops in the advanced firewall config and it still didnt work...
Davit2005 Posted September 4, 2012 Posted September 4, 2012 I actually forgot to do it in the image and done it through policy without a problem. Can you connect any other service via WMI (i.e. VAMT) to jus check and make sure the port is open on the laptop. From memory I also think you need to make Domain Admins a member of the administrators group on the local PC for SCCM client to install.
scottpowers82 Posted September 5, 2012 Posted September 5, 2012 Try adding the SCCM server's computer account to the local administrators group (try by hand first to make sure it works, then can be done through group policy). Seemed to do the trick for me. 1
RabbieBurns Posted October 9, 2012 Author Posted October 9, 2012 right still struggling to get the client to push out from SCCM so Im going to look at using just group policy Ive imported the ADM files for it but not sure what settings need to be configured?
RabbieBurns Posted October 9, 2012 Author Posted October 9, 2012 Think I figured it out and its installing via GPO OK
midiman Posted January 27, 2013 Posted January 27, 2013 Think I figured it out and its installing via GPO OK Hi did you ever get this to work? I'm having the same problems.
RabbieBurns Posted February 19, 2013 Author Posted February 19, 2013 Nope. Still having the same problem. The only way I seem to be able to get it to work is to move computers account in AD to the default Computers container, and then manually tun off the firewall on the device. If I move the computer account to another container, which has a group policy to explicitely disable all windows firewall, the client fails to install. Using CMTRACE I can see the folliwing: What might I have done wrong? Anyone?
gshaw Posted February 19, 2013 Posted February 19, 2013 Not sure if 2012 is the same as previous versions but you used to need the "Remote Administration" option allowed in the firewall
RabbieBurns Posted February 19, 2013 Author Posted February 19, 2013 but what i don't understand is why it still fails even when i explicitly disable the firewall in GPO?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now