Windows Firewall must be enabled on each host to allow Remote Administration. This option is not enabled by default



Similar documents
Troubleshooting Guide

Kepware Technologies Remote OPC DA Quick Start Guide (DCOM)

Setting up DCOM for Windows XP. Research

Before deploying SiteAudit it is recommended to review the information below. This will ensure efficient installation and operation of SiteAudit.

Nagios XI Monitoring Windows Using WMI

XStream Remote Control: Configuring DCOM Connectivity

Setup non-admin user to query Domain Controller event log for Windows2003

Application Note 8: TrendView Recorders DCOM Settings and Firewall Plus DCOM Settings for Trendview Historian Server

Installing and Configuring Active Directory Agent

Installing GFI Network Server Monitor

DCOM Setup. User Manual

SCCM Client Checklist for Windows 7

Windows Firewall Configuration with Group Policy for SyAM System Client Installation

Universal Management Service 2015

DCA Local Print Agent Push Install

Configuring WMI on Windows Vista and Windows Server 2008 for Application Performance Monitor

Tool Tip. SyAM Management Utilities and Non-Admin Domain Users

Web based training for field technicians can be arranged by calling These Documents are required for a successful install:

Installation Notes for Outpost Network Security (ONS) version 3.2

DCOM settings for computer-to-computer communication between OPC servers and OPC clients

OPC and DCOM: 5 things you need to know Author: Randy Kondor, B.Sc. in Computer Engineering

DC Agent Troubleshooting

TrueEdit Remote Connection Brief

Lab - Configure a Windows 7 Firewall

1. Installation Overview

Enterprise. Insights. Active Directory Integration: Installation and Setup Guide. v1.0.5

Deploying BitDefender Client Security and BitDefender Windows Server Solutions

OPC Server Machine Configuration

DigitalPersona Pro Server for Active Directory v4.x Quick Start Installation Guide

Create, Link, or Edit a GPO with Active Directory Users and Computers

LOCAL PRINT AGENT OVERVIEW

All Tech Notes and KBCD documents and software are provided "as is" without warranty of any kind. See the Terms of Use for more information.

Scan to SMB(PC) Set up Guide

RSA Security Analytics

Core Protection for Virtual Machines 1

Installation Overview

InduSoft Web Studio + Windows XP SP2. Introduction. Initial Considerations. Affected Features. Configuring the Windows Firewall

DESLock+ Basic Setup Guide Version 1.20, rev: June 9th 2014

Administrator s Guide

How To Create An Easybelle History Database On A Microsoft Powerbook (Windows)

Windows Firewall Exceptions Configuring Windows Firewall Exceptions for Docusnap

This document describes the installation of the Web Server for Bosch Recording Station 8.10.

Configure and enable remote access for windows operating system

Abstract. This is the MySQL Windows extract from the MySQL 5.1 Reference Manual. For legal information, see the Legal Notices.

CANON FAX L360 SOFTWARE MANUAL

Installing and Configuring WhatsUp Gold

Lab - Configure a Windows Vista Firewall

Important Notes for WinConnect Server VS Software Installation:

Administrator s Guide

Microsoft Windows DCOM Configuration. Windows XP SP3 and Server 2003 SP2 Configuration Guide

Configuring a Custom Load Evaluator Use the XenApp1 virtual machine, logged on as the XenApp\administrator user for this task.

Freshservice Discovery Probe User Guide

Deploying BitDefender Client Security and BitDefender Windows Server Solutions

Select Correct USB Driver

Intelligent Power Protector User manual extension for Microsoft Virtual architectures: Hyper-V 6.0 Manager Hyper-V Server (R1&R2)

Dell UPS Local Node Manager USER'S GUIDE EXTENSION FOR MICROSOFT VIRTUAL ARCHITECTURES Dellups.com

MONITORING WINDOWS WITH NETCRUNCH 7 P A G E 1

MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # )

How to Connect to Berkeley College Virtual Lab Using Windows

OneStop Reporting 3.7 Installation Guide. Updated:

DCOM Configuration for Windows NT4, Windows 2000, Windows XP, and Windows XP Service Pack 2

Legal Notes. Regarding Trademarks KYOCERA Document Solutions Inc.

Installing GFI Network Server Monitor

Microsoft XP Professional Remote Desktop Connection

INSTALLING MICROSOFT SQL SERVER AND CONFIGURING REPORTING SERVICES

ms-help://ms.technet.2005mar.1033/security/tnoffline/security/smbiz/winxp/fwgrppol...

Active Directory Integration: Install and Setup Guide. Insights

enicq 5 System Administrator s Guide

In this lab you will explore the Windows XP Firewall and configure some advanced settings.

Network Setup Instructions

ACTIVE DIRECTORY DEPLOYMENT

DUKANE Intelligent Assembly Solutions

LICENSE MANAGER VERSION 7.2. Procedures for Use of Sentinel LM7.2 Server for CHEMCAD. rev

WhatsUp Event Analyst v10.x Quick Setup Guide

Parallels Mac Management for Microsoft SCCM

TestElite - Troubleshooting

WMI Collecting Windows Logs

FTP Server Configuration

Password Manager Windows Desktop Client

CONFIGURING MICROSOFT SQL SERVER REPORTING SERVICES

Networking Lab - Vista Public Network Sharing

Lab - Configure a Windows XP Firewall

Software Installation Requirements

Parallels Mac Management for Microsoft SCCM 2012

NETWRIX PASSWORD MANAGER

Autograph 3.3 Network Installation

OPC Unified Architecture - Connectivity Guide

Web Deployment on Windows 2012 Server. Updated: August 28, 2013

User Manual. Onsight Management Suite Version 5.1. Another Innovation by Librestream

HP Device Manager 4.6

Reference and Troubleshooting: FTP, IIS, and Firewall Information

intertrax Suite resource MGR Web

Nexio Connectus with Nexio G-Scribe

File and Printer Sharing with Microsoft Windows

Windows XP Service Pack 2 Issues

NETWRIX ACCOUNT LOCKOUT EXAMINER

FlexSim LAN License Server

EventTracker: Support to Non English Systems

NetWrix USB Blocker. Version 3.6 Administrator Guide

IIS, FTP Server and Windows

Transcription:

SiteAudit Knowledge Base Local Printer Discovery August 2011 In This Article: Windows Firewall Settings COM Configuration SiteAudit provides discovery and management of printers attached to Windows hosts via USB or Parallel ports. This operations document is about Windows Firewall settings to allow SiteAudit to manage these printers. Windows Firewall By default Windows Firewall settings on Windows XP SP2, Windows 2003 SR1 (and above) do not allow SiteAudit to discover and manage printers attached to. Several settings need to be changed in order to allow this management. This document describes the manual process needed to make this possible. The steps outlined below could be combined in a script and pushed out to each host in the network using a tool such as Group Policy Management Console. Remote Administration/WMI Exceptions Windows Firewall must be enabled on each host to allow Remote Administration. This option is not enabled by default 1. Using the Command prompt 1. Click Start, click Run, type cmd, and then click OK. 2. netsh firewall set service RemoteAdmin enable For Windows 7 and newer operating systems, use the following command instead: netsh advfirewall firewall set rule group="windows management instrumentation (wmi)" new enable=yes 2. Using the Group Policy editor 1. Click Start, click Run, type gpedit.msc, and then click OK. 2. Under the Local Computer Policy heading, double-click Computer Configuration. 3. Double-click Administrative Templates, Network, Network Connections, and then Windows Firewall. Netaphor SiteAudit Software Documents Rev. 2.0

4. If the computer is in the domain, then double-click Domain Profile; otherwise, double-click Standard Profile. 5. Click Windows Firewall: Allow remote administration exception. 6. On the Action menu, select Properties. 7. Click Enable, and then click OK. DCOM Distributed COM (DCOM) must be enabled. This option is the default. 3. In the My Computer Properties dialog box, click the Properties 4. Check the box for Enable Distributed COM on this computer. Launch Permissions Windows Firewall must allow the credentials being used to allow Remote Launch Permissions This option should be the default if the credentials of a user that is the member of the Local Administrators group is being used. 3. In the My Computer Properties dialog box, click the COM Security 4. Under Launch and Activation Permissions, click Edit Limits. 5. In the Launch Permission dialog box, follow these steps if your name or your group does not appear in the Groups or user names list: 1. In the Launch Permission dialog box, click Add. 2. In the Select Users, Computers, or Groups dialog box, add your name and the group in the Enter the object names to select box, and then click OK. 2011 Netaphor Confidential CHANNEL PARTNER ONLY 2 Last Updated: 11/04/27

6. In the Launch Permission dialog box, select your user and group in the Group or user names box. In the Allow column under Permissions for User, select Remote Launch and select Remote Activation, and then click OK. 7. When connecting to a target machine with a local account in Windows Vista and later, the user must explicitly be given full allow Launch and Activation Permission. 8. When connecting to a to a target machine with a domain account in Windows Vista and later, the domain user must be either explicitly added to the Administrators group of the machine, or a member of the domain's Domain Admins (and the Domain Admins group is a member of Administrators). Verify the Administrators group has full Launch and Activation Permission allowances. Access Permissions Windows Firewall must allow the credentials being used to allow Remote Access Permissions. These permissions are only required if the host where SiteAudit is running is in a different domain or workgroup from the target domain or workgroup This option is not the default. 3. In the My Computer Properties dialog box, click the COM Security 4. Under Access Permissions, click Edit Limits. 5. In the Access Permission dialog box select ANONYMOUS LOGON name in the Group or user names box. In the Allow column under Permissions for User, select Remote Access, and then click OK. 2011 Netaphor Confidential CHANNEL PARTNER ONLY 3 Last Updated: 11/04/27

Namespace Permissions WMI must allow the credentials being used to have full access. This option should be the default if the credentials of a user that is the member of the Local Administrators group is being used. 1. In the Control Panel, double-click Administrative Tools. 2. In the Administrative Tools window, double-click Computer Management. 3. In the Computer Management window, expand the Services and Applications tree and double-click the WMI Control. 4. Right-click the WMI Control icon and select Properties and then select the Security 5. Click on the Security button. 6. Ensure that the credentials which you will be using (typically the local Administrators group) will have full control, and that the namespace privileges apply to the current and 2011 Netaphor Confidential CHANNEL PARTNER ONLY 4 Last Updated: 11/04/27

all sub namespaces. Remote Enable must be selected as a minimum. When connecting to a target machine with a local account in Windows Vista and later, the user must be listed explicitly. Remote Credentials On Windows XP Professional make sure that remote logons are not being coerced to the GUEST account ("Force Guest", which is enabled by default computers that are not attached to a domain). This option is not the default. 1. Click Start click Run, type Secpol.msc, and then click OK. 2. Select Local Policies and then select Security s. 3. Find the setting Network access: Sharing and security model for local accounts. Make sure it is set to Classic. 4. If you change the setting you must restart your computer. 2011 Netaphor Confidential CHANNEL PARTNER ONLY 5 Last Updated: 11/04/27