Configuring Firewall Settings For Configuration Manager 2012 R2



Similar documents
Windows Firewall Configuration with Group Policy for SyAM System Client Installation

SCCM Client Checklist for Windows 7

Creating and Issuing the Workstation Authentication Certificate Template on the Certification Authority

ms-help://ms.technet.2005mar.1033/security/tnoffline/security/smbiz/winxp/fwgrppol...

Secunia CSI integrated with WSUS (SCCM)

Tool Tip. SyAM Management Utilities and Non-Admin Domain Users

Click Studios. Passwordstate. Password Discovery, Reset and Validation. Requirements

How To Backup SCCM 2012 R2 Server

Basic Exchange Setup Guide

RSA Security Analytics

freesshd SFTP Server on Windows

Windows Firewall Exceptions Configuring Windows Firewall Exceptions for Docusnap

HP Universal Print Driver Series for Windows Active Directory Administrator Template White Paper

Install MS SQL Server 2012 Express Edition

Setup Guide for Exchange Server

Web based training for field technicians can be arranged by calling These Documents are required for a successful install:

Step-By-Step Guide to Deploying Lync Server 2010 Enterprise Edition

F-SECURE MESSAGING SECURITY GATEWAY

WORKING WITH WINDOWS FIREWALL IN WINDOWS 7

Basic Exchange Setup Guide

SOLARWINDS ORION. Patch Manager Evaluation Guide for ConfigMgr 2012

Click on Start Control Panel Windows Firewall. This will open the main Windows Firewall configuration window.

Overview - Using ADAMS With a Firewall

SCCM How to guide deploying SCCM Client, setting up SUP and SCEP. Hans Chr. Andersen

Laptop Backup - Administrator Guide (Windows)

Installing Kaspersky Security Center 10.0 on Microsoft Windows Server 2012 Core Mode

PrivateWire Gateway Load Balancing and High Availability using Microsoft SQL Server Replication

Spam Marshall SpamWall Step-by-Step Installation Guide for Exchange 5.5

CREATING AN IKE IPSEC TUNNEL BETWEEN AN INTERNET SECURITY ROUTER AND A WINDOWS 2000/XP PC

How do I load balance FTP on NetScaler?

Deploying Windows 7 Using SCCM 2012 R2

SQL Server Mirroring. Introduction. Setting up the databases for Mirroring

Architecture and Data Flow Overview. BlackBerry Enterprise Service Version: Quick Reference

Network Load Balancing

How to Setup SQL Server Replication

Biznet GIO Cloud Connecting VM via Windows Remote Desktop

Configuring Windows Server Clusters

Configuration Guide. BES12 Cloud

Knowledge Base Article: Article 218 Revision 2 How to connect BAI to a Remote SQL Server Database?

Configuration Manager 2012 SC2012 ConfigMgr SP1 MP Replica Configuration Guide

Windows Firewall must be enabled on each host to allow Remote Administration. This option is not enabled by default

Case Closed Installation and Setup

Windows XP Service Pack 2 Windows Firewall Group Policy Setup for Executive Software Products

Installation Guide. . All right reserved. For more information about Specops Inventory and other Specops products, visit

Using TestLogServer for Web Security Troubleshooting

SOLARWINDS ORION. Patch Manager Administrator Guide

CONFIGURING MICROSOFT SQL SERVER REPORTING SERVICES

Overview - Using ADAMS With a Firewall

Connection and Printer Setup Guide

F-Secure Messaging Security Gateway. Deployment Guide

Configuring Load Balancing

SOLARWINDS ORION. Patch Manager Evaluation Guide

Windows Server Firewall Configuration

CIMHT_006 How to Configure the Database Logger Proficy HMI/SCADA CIMPLICITY

Specops Command. Installation Guide

How To Manage Ip Address Management In Windows Server 2012 (Gipam)

User Document. Adobe Acrobat 7.0 for Microsoft Windows Group Policy Objects and Active Directory

Troubleshooting Guide

Configuration Guide BES12. Version 12.3

Dolphin Ocean Server and Dolphin Mobile Client Installation and Configuration instructions

MailMarshal SMTP in a Load Balanced Array of Servers Technical White Paper September 29, 2003

Setting Up a Unisphere Management Station for the VNX Series P/N Revision A01 January 5, 2010

HDA Integration Guide. Help Desk Authority 9.0

Installing T-HUB on multiple computers

Configuring a Custom Load Evaluator Use the XenApp1 virtual machine, logged on as the XenApp\administrator user for this task.

EMR Link Server Interface Installation

Install and configure server

LOOK BEHIND THE SCENES: WINDOWS SERVER 2012 FIREWALL AT VOLKSWAGEN AG

Terminal Server Citrix MetaFrame Installation Guide

ACTIVE DIRECTORY DEPLOYMENT

Basic instructions for configuring PPP MSSQL Express Firewall Settings for Server 2008 and Windows 7 Operating Systems

EventTracker: Support to Non English Systems

Kaseya Server Instal ation User Guide June 6, 2008

How To - Implement Clientless Single Sign On Authentication with Active Directory

Idera SQL Diagnostic Manager Management Pack Guide for System Center Operations Manager. Install Guide. Idera Inc., Published: April 2013

enicq 5 System Administrator s Guide

Installing Policy Patrol with Lotus Domino

ilaw Server Migration Guide

Installing Windows Server Update Services (WSUS) on Windows Server 2012 R2 Essentials

Nagios XI Monitoring Windows Using WMI

How To Manage Storage With Novell Storage Manager 3.X For Active Directory

DameWare Server. Administrator Guide

SecureIT Plus Firewall Features and Functionality

Quick Note 026. Using the firewall of a Digi TransPort to redirect HTTP Traffic to a proxy server. Digi International Technical Support December 2011

BlackBerry Enterprise Service 10. Version: Configuration Guide

WHITE PAPER Citrix Secure Gateway Startup Guide

Enabling Remote Management of SQL Server Integration Services

Velocity Web Services Client 1.0 Installation Guide and Release Notes

Configuration Guide BES12. Version 12.2

Immotec Systems, Inc. SQL Server 2005 Installation Document

REQUIREMENTS AND INSTALLATION OF THE NEFSIS DEDICATED SERVER

Installing Policy Patrol on a separate machine

Upgrade Guide BES12. Version 12.1

Parallels Mac Management for Microsoft SCCM

Using Double-Take Through a Firewall

DriveLock Quick Start Guide

Transcription:

prajwaldesai.com http://prajwaldesai.com/configuring-firewall-settings-for-configuration-manager-2012-r2/ Configuring Firewall Settings For Configuration Manager 2012 R2 Prajwal Desai In this post we will look at the steps for configuring firewall settings for configuration manager 2012 R2. System Center 2012 R2 Configuration Manager is a distributed client/server system. The distributed nature of Configuration Manager means that connections can be established between site servers, site systems, and clients. Some connections use ports that are not configurable, and some support custom ports you specify. You must verify that the required ports are available if you use any port filtering technology such as firewalls, routers, proxy servers, and IPsec. To know more about ports used by configuration manager 2012 R2 click here. Note In order to successfully use client push to install the Configuration Manager 2012 R2 client, you must add the following as exceptions to the Windows Firewall. If there is a firewall between the site system servers and the client computer, confirm whether the firewall permits traffic for the ports that are required for the client installation. 1) File and Printer Sharing 2) Windows Management Instrumentation (WMI) We will create an inbound and outbound rule, add File and Printer sharing service as exception to firewall and an Inbound rule to allow WMI. We will perform this activity on the Domain Controller. Click on Server Manager, click on Tools, open Group policy management console. Right Click on the domain and Create a GPO.

Provide a name to the GPO and click on OK.

Right click on the policy that you created and click on Edit. Expand computer configuration, Windows settings, Security settings, Windows Firewall with advanced security. Right click on Inbound rules and click on New Rule Click on Predefined and select File and Printer Sharing. Click on Next.

Don t change anything here, click on Next.

Click on Allow the connection. Click Finish.

Now we will create an outbound rule to allow File and Printer sharing. Right click on the Outbound Rule and click on New Rule. Choose Predefined and select File and Printer Sharing. Click on Next.

Click on Allow the connection. Click Finish.

Now we will create an Inbound Rule to allow the WMI service on our Firewall. So right click on Inbound Rule and click on New Rule. Click on Predefined and select Windows Management Instrumentation (WMI). Click on Next.

Click Next.

Choose Allow the connection and click Finish.

Opening Ports for SQL Replication We will now see the steps to open the ports for SQL Replication. Please note that Configuration Manager does not support dynamic ports. Because SQL Server named instances by default use dynamic ports for connections to the database engine, when you use a named instance, you must manually configure the static port that you want to use for intrasite communication. This point has been discussed while installing SQL server for configuration manager 2012 R2. Why should the ports 1433 and 4022 opened on Firewall?? Port 1433 SQL Server listens for incoming connections on a particular port. The default port for SQL Server is 1433. It applies to routine connections to the default installation of the Database Engine, or a named instance that is the only instance running on the computer. Port 4022 This is SQL Service Broker, though there is no default port for SQL Server Service Broker, but this is the port that we allow inbound on our firewall.

Site System roles that communicate directly with the SQL Server database Application Catalog web service point Certificate registration point role Enrollment point role Management point Site server Reporting services point SMS Provider SQL Server to SQL Server By default, Microsoft Windows enables the Windows Firewall, which closes port 1433 to prevent Internet computers from connecting to a default instance of SQL Server on your computer. Connections to the default instance using TCP/IP are not possible unless you reopen port 1433. We will now create a group policy to open TCP ports 1433 and 4022. Open the Group Policy Management console. Create a new policy and provide a name for the policy. Right Click the policy and edit it.

In the Windows GP management console, expand computer configuration, Windows settings, Security settings, Windows firewall with advanced security. Right click on Inbound Rule and create an Inbound Rule and select Port. Click on Next. Select TCP, and specify port 1433 in specific local ports. Click Next.

Click on Allow connection and click on Next.

The firewall rule will be applied for all the 3 profiles. Click on Next.

Name the rule as TCP Inbound 1433. Click on Finish.

Similarly create an Inbound Rule to allow port 4022. choose TCP and specify the port number as 4022. Click on Next.

Click on Allow the connection. Click on Next. Select Domain, Private and Public and click on Next. Provide the name as TCP Inbound 4022 to identify the rule. Click on Finish.

We have allowed TCP inbound ports 1433 and 4022 on our firewall.

Run the gpupdate /force command on the domain controller and on any of the client machine, launch the command prompt and type the command gpupdate /force and hit enter. In the same command prompt, type the command rsop.msc. This will show the resultant set of policies, group policies that are applied to this client. Expand Administrative Templates and click on Extra Registry Settings. On the right side pane you will find that the policies that we created are applied on the machine.

~ Resultant Set of Policy l- Ie- $1 File Action View Favorites Window Help I~ I ~ lim @tl ~ [ill J1 sccmadmin on SCCM - RSoP letting State GPO Name A Computer Configuration 4110 @] SOFTWARE\Policies\ Microsoft\WindowsFirewaii\ FirewaiiRules\ FPS-NB_Datagram-ln-UDP v2.201action=... Client Push Policy Settings ~ t) Software Settings ~ SOFTWARE\Policies\ Microsoft\WindowsFirewaii\ FirewaiiRules\ FPS-NB_Name-ln-UDP v2.201action=... Client Push Policy Settings ~ ILl Windows Settings @'] SOFTWARE\Policies\ Microsoft\ WindowsFirewaii\ FirewaiiRules\{D 1152640-06EC -4850-802... v2.201action=... SQL Ports For SCCM 2012 R2 A ~ Administrative Templates @] SOFTWARE\Policies\ Microsoft\WindowsFirewaii\ FirewaiiRules\ FPS-LLMNR-Out-UDP v2.201action=... Client Push Policy Settings ~ Extra Registry Settings ~ SOFTWARE\ Policies\ Microsoft\WindowsFirewaii\ FirewaiiRules\ FPS-LLMNR-In-UDP v2.201action=... Client Push Policy Settings A 11!, User Configuration @] SOFTWARE\Policies\ Microsoft\ WindowsFirewaii\ FirewaiiRules\ WMI-ASYNC -In-TCP v2.201action=... Client Push Policy Settings ~ IL!I Software Settings @] SOFTWARE\Policies\ Microsoft\WindowsFirewaii\ FirewaiiRules\ FPS-NB_Name-Out-UDP v2.201action=... Client Push Policy Settings " E!J Windows Settings @] SOFTWARE\Policies\ Microsoft\WindowsFirewaii\ FirewaiiRules\ FPS-NB_Datagram-Out-U... v2.201action=... Client Push Policy Settings ~ Iii Security Settings @] SOFTWARE\Policies\ Microsoft\WindowsFirewaii\ FirewaiiRules\ FPS-SMB-Out-TCP v2.201action=... Client Push Policy Settings ~ SOFTWARE\Policies\ Microsoft\ WindowsFirewaii\ FirewaiiRules\ WMI-WINMGMT -In-TCP v2.201action=... Client Push Policy Settings @'] SOFTWARE\Policies\ Microsoft\WindowsFirewaii\ FirewaiiRules\ FPS-RPCSS-In-TCP v2.201action=... Client Push Policy Settings @] SOFTWARE\Policies\ Microsoft\WindowsFirewaii\ Firewa11Rules\ FPS-ICMP6-ERQ-Out v2.201action=... Client Push Policy Settings ~ SOFTWARE\ Policies\ Microsoft\WindowsFirewaii\ FirewaiiRules\ FPS-SpooiSvc-ln -TCP v2.201action=... Client Push Policy Settings @] SOFTWARE\Policies\ Microsoft\WindowsFirewaii\ Firewa11Rules\ FPS-ICMP4-ERQ-In v2.201action=... Client Push Policy Settings @] SOFTWARE\Policies\ Microsoft\WindowsFirewaii\ Firewa11Rules\ FPS-ICMP4-ERQ-Out v2.201action=... Client Push Policy Settings @] SOFTWARE\Policies\ Microsoft\WindowsFirewaii\ FirewaiiRules\ FPS-SMB-In-TCP v2.201action=... Client Push Policy Settings @] SOFTWARE\Policies\ Microsoft\WindowsFirewaii\ Firewa11Rules\{690FFD21 -A383-4FA6-B65... v2.201action=... SQL Ports For SCCM 2012 R2 ~ SOFTWARE\Policies\ Microsoft\WindowsFirewaii\ FirewaiiRules\ FPS-NB_Session-ln -TCP v2.201action=... Client Push Policy Settings @'] SOFTWARE\Policies\ Microsoft\WindowsFirewaii\ FirewaiiRules\WMI-RPCSS-In -TCP v2.201action=... Client Push Policy Settings @] SOFTWARE\Policies\ Microsoft\WindowsFirewaii\ FirewaiiRules\ FPS-NB_Session-Out-TCP v2.201action=... Client Push Policy Settings ~ SOFTWARE\ Policies\ Microsoft\WindowsFirewaii\ Firewai1Rules\ FPS-ICMP6-ERQ-In v2.201action=... Client Push Policy Settings @] SOFTWARE\Policies\ Microsoft\WindowsFirewaii\ PolicyVersion 534 Client Push Policy Settings <lj Ill LJ_> I< I Ill II > I Extended A Standard ~ T'\ 11'\. ~I 1(11\IV(::I.!Vt;~cU.\..ilJll!