Firewall ports needed for rpc error in powershell

In my enviroment we use several different DMZ's to host our servers in. This creates a situation where some of the computers in the domains are in different subnets.  I am trying to run a script in one domain in which all the computers are
in the same subnet except for 2. In this case there is a firewall between the two subnets i am describing. When i try and run my script i recieve the error below. I have verified the following ports are open on the firewall.
TCP 5985, 5986, 445, 389    TCP\UDP 135
I have monitored our firewall and the ports being blocked when i run my script are TCP 4754 on one server and 5002 on the other. I believe these are DCOMM ports. What other ports or range of ports, or any other ports, do I need to open to resolve
the RPC error? I do not want to just open a bunch of unneeded ports between my DMZ's. I could just open these 2 ports and resolve the issue for now, but i am trying to make this a powershell friendly enviroment, if you take my meaning. I should mention all
local firewalls are turned off on the servers and the script runs fine on all other servers in the subnet.
Thank You in advance for your help
Get-WmiObject : The RPC server is unavailable. (Exception from HRESULT: 0x800706BA)
At C:\Users\jthomas99\Desktop\Get-IPDetails.ps1:14 char:16
+    $Networks = Get-WmiObject Win32_NetworkAdapterConfiguration -ComputerName $Co ...
+                ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : InvalidOperation: (:) [Get-WmiObject], COMException
    + FullyQualifiedErrorId : GetWMICOMException,Microsoft.PowerShell.Commands.GetWmiObjectCommand
Thanks for your help

Here is the DCOM firewall configuration document.  It should be given to your firewall admins and they need to pay special attention to setting up the DCOM port forwarding rules.
http://support.microsoft.com/kb/154596/en-us
There are also instructions on how to configure DCOM ports to work with WAN/Internet access issues.
If you are looking to obtain remote management over a WAN or the Internet you can and should set up WMF as it can be run over a fully encrypted HTTPS port and it does not require odd dynamic port allocation
as does RPC.
You can also set up PowerShell Web Service which does not require dynamic ports and can be routed over any port.  It uses the browser to open a PowerShell session on a remote server that can have delegated access to other servers.  DCOM cannot
do this without making many dangerous changes t your network.
http://technet.microsoft.com/en-us/library/hh831611.aspx
¯\_(ツ)_/¯

Similar Messages

  • Firewall ports needed for remote management?

    Hey guys,
    Does anyone know the ports needed so that I can remotely connect to other Win7 computer through compmgmt.msc, regedit, msinfo32, remote rsop.msc, etc?  I think those are just rpc connections, but not sure.  Is it tcp 135?
    Thanks,
    Dan
    Dan Heim

    Hi Dan,
    Based on my research, remote desktop connections are via RDP instead of RPC, so the ports for Remote Desktop to work, 3389 and 443 are used mostly.
    More information for you:
    Overview of Remote Desktop Gateway
    http://technet.microsoft.com/en-us/library/cc731150.aspx
    What ports are used by a RDS deployment?
    http://social.technet.microsoft.com/wiki/contents/articles/16164.what-ports-are-used-by-a-rds-deployment.aspx
    Getting Remote Desktop to
    work thru most firewalls
    http://blog.jordanterrell.com/post/Getting-Remote-Desktop-to-work-thru-most-firewalls.aspx
    Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.
    How RPC Works
    http://technet.microsoft.com/en-us/library/cc738291(v=WS.10).aspx
    Best Regards,
    Amy Wang

  • What Network Firewall Ports Needed For Music Store?

    My PC is on a network that is firewalled to the the Internet. All ports are blocked except for those explicitely enabled, such as port 25 for E-mail, port 80 for browsing, etc.
    When the Windows Firewall is disabled, my PC cannot get past the the Music Store's home page. All links are inoperative.
    When I connect my PC to another router/firewall, that bypasses my network's firewall, I can navigate the music store.
    I believe I have a blocked port issue when the PC is connected to my network.
    Can anyone tell me what Internet/TCP ports I need to have open for the iTunes music store and for QuickTime?
    Thanks for the assist.
    Regards.

    hiya!
    Since you say that iTunes is using standard browser ports, then perhaps it's my network's Proxy Server that iTunes doesn't work well with.
    it might be worth checking on these possibilities:
    iTunes for Windows can't access the Internet if proxy settings are incorrect
    ... but also see:
    iTunes for Windows: Music Store - Using With Internet Filters or Accelerators
    love, b

  • Snow Leopard Firewall Ports Needed

    Is there a document that contains all of the ports needed for iCal Server, Address Book Server, and all of the other mobile services? The documentation says to check the resources however, I have not been able to find anything specifically from apple.
    Thanks!
    Jeff

    I had the same problem as you, by the sounds of it. When I installed Snow Leopard Server on a mini, it went through the motions of configuring the attached Airport base station NAT settings to support the services I had turned on. Unfortunately, that configuration either didn't stick, or the Airport lost the settings in the restart. Here's where I posted a question about this experience: http://discussions.apple.com/thread.jspa?messageID=10318987&#10318987
    Like you, I've been redirected to that "well know" list on several occasions, but it doesn't quite answer the question we both seem to have which is: +If Snow Leopard Server had successfully configured the NAT port settings on my Airport router, what would that configuration look like?+ Or, put in other terms: +What are just the ports I need to open on my Airport router to adequately support my installation of Snow Leopard Server?+
    Of course, it all depends on what services you have enabled, so it would be helpful if the list could be broken down by service type.
    Yes, the sure would save wading through that massive "well know" ports list to find just the few you need to manually configure the Airport...

  • What is the Firewall ports need to be open for TED distribution working properly

    Hi ,
    May I know what ports need to be open at the firewall in order the TED
    distribution to be working properly.
    I suspect it is firewall problem because the inventoried server which
    is install at the same segment with the TED distributor server, I manage to
    push the policy and collect inventory data , but for those inventoried
    server which is install at the remote site, I fail to push the TED into the
    server. At the TED distributor server, the log say that computer refused
    connection. And there is a firewall in between the TED distributor server
    and the remote inventoried server.
    Thank you.
    Steven Foong

    TED is using 1229
    Ron
    <[email protected]> wrote in message
    news:X7lAe.2193$[email protected]..
    > Hi ,
    >
    > May I know what ports need to be open at the firewall in order the
    TED
    > distribution to be working properly.
    >
    > I suspect it is firewall problem because the inventoried server which
    > is install at the same segment with the TED distributor server, I manage
    to
    > push the policy and collect inventory data , but for those inventoried
    > server which is install at the remote site, I fail to push the TED into
    the
    > server. At the TED distributor server, the log say that computer refused
    > connection. And there is a firewall in between the TED distributor server
    > and the remote inventoried server.
    >
    > Thank you.
    >
    >
    > Steven Foong

  • Firewall Ports directions for Client Push Installation

    Hello,
    i take offer a running SCCM 2012 R2 Client Management but there is no Client Push implemented.
    So i will now use Client Push and we open the Ports 135 and 445 now i have one Question to use RPC Dynamic Ports,
    they are only from Server -to-> Client or both direction?
    I read a lot of them but nobody wrote about the directions, my problem is that our SCCM 2012 is installed in a management network and the connect to the clients are controlled with a Firewall and now for a change i must known the direction to change it.
    The Port description from MS i read often but not very helpful with direction. :)
    with best regards
    André

    To add-on to Torsten. It is also possible to restrict your dynamic RPC ports, as explained at articles like these:
    http://www.windowsnetworking.com/kbase/WindowsTips/WindowsServer2008/AdminTips/Admin/DefaultDynamicPortRange.html
    http://support.microsoft.com/kb/154596
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude
    Have you ever successfully done this? I tried once early in CM07 and it didnt' work. Submitted my findings to MS and a reference from the CM docs to the article you posted was removed from the CM docs.
    John Marcum | Microsoft MVP - Enterprise Client Management
    My blog: System Center Admin | Twitter:
    @SCCM_Marcum | Linkedin:
    John Marcum

  • Which Firewall Ports need to be opened FTP Authentication Problem

    Ok, which ports need to be opened on the firewall to allow me to access another sites FTP. I opened 20-21, but still no dice. When I turn off my firewall, I can access them without a problem.
    I figure it is some other port that is being used, but I have no idea what one.

    Are you running apple default FTP service?
    In SA you have al least 2 subnets to control in Firewall Service, one pointng to you LAN, the other (any) is for incoming connections.
    Ftp service requires open ports on 20-21 , this is called passive mode restriction, if you have problems connecting you have to open also some higher ports (ex: 49152-65534) to enable non-passive mode.
    Try to read /Library/FTPServer/Configuration/ftpaccess and look for a line like this :
    passive ports youripnumber 49151 49155 (if not add it)
    In Firewall > Settings > Service add ports 49151-49155 to allow only traffic by clicking the "+" button to add the ports. Save and restart Firewall.

  • Ports needed for CiscoWorks managment

    I am Instaling AP and I don't know which ports should be opened on switch for communication between Access Point and CiscoWork. For now we open all ports to CiscoWorks station, but we want to cut it as much as its possible. Also we've got problems with configuring CiscoWorks to work with AP (AiroNet1130) now it's working but we arn't sure which options are nessesery - so maybe someone could tell me what is exacly needed for this
    Thanks for all replays
    Regards
    Adam

    Here's the official list for CiscoWorks WLSE:
    http://www.cisco.com/en/US/customer/products/sw/cscowork/ps3915/products_user_guide_chapter09186a008052db6f.html
    I thought I saw a post a while ago about some undocumented ports used by WLSE too, but can't find it at the moment.

  • POP UP needed for an ERROR while performing an action

    Hello Experts,
    I need your help in creating a pop up for an error that occurs while performing an action and the value for a certain field in an infotype is incorrect. Right now the error just gets displayed in the bottom of the screen. Immediate responses would be highly appreciated!

    check here http://scn.sap.com/community/erp/hcm/employee-self-service/blog/2013/12/02/how-to-show-pop-up-s-in-wda-hcmpf http://scn.sap.com/thread/3497688

  • Do router/firewall ports need to be opened for higher bandwidth?

    Currently I use iChat between myself and my mom across town with decent results. The video is blurred but extremely smooth.
    We are both on broadband with different ISPs (Telus & Shaw) with our own routers. None of the ports on either router are open for iChat yet we connect fine.
    If I opened up iChat ports on both routers will that allow more bandwidth to flow through the video resulting in less blur?

    Hi
    No it will not give any more bandwidth, seeing you have iChat working i would leave the ports alone
    Have you both set the Quicktime settings, goto sys prefs/quicktime/streaming/streaming speed set what you get from your ISP go no higher then 1.5mbps(dont use automatic)
    In ichats prefs click on video and change bandwidth limit to NONE.
    Restart iChat.
    Tony

  • Firewall Ports Required for NAC manager to manage/add Cisco switch

    Hi,
    I am trying to add cisco switches to the NAM, however i am not able to add the switch as I am getting the error "unable to control switch" I have tried to open ports 161-162 on the firwall; if i was to allow any traffic between the NAM and switch, the cisco NAM is able to add/manage the switch.
    Not sure what other ports may be required for cisco NAM to manage the switch?
    Thanks.

    Hi,
    AFAIK, only the UDP ports 161-162 for the SNMP communication need to be open.
    Please make sure you have configured the correct port on the switch:
    (config)# snmp-server host 172.16.1.61 traps version 2c cam_v2 udp-port 162 mac-notification snmp
    If still not working i would check the logs on the firewall for any blocked traffic between the CAM and the switch.
    HTH,
    Tiago
    If  this helps you and/or  answers your question please mark the question  as "answered" and/or rate  it, so other users can easily find it.

  • DA server within a DMZ - ports needed for internal network

    Hi,
     I'm planning on adding a domain joined DA server in my DMZ. The DA server will have 2 NICs, one for the internal network and the other for the external. I'll be using two consecutive public IPv4 addresses.
    On my external firewall I'll be opening the following ports for my DA server:
    - Port 443 inbound and outbound
    - UDP 3544 inbound and outbound.
    On my Juniper firewall between the internal network and DMZ I'll be opening the following bi directional ports between my DC and DA server:
    - IP Protocol 41 inbound and outbound.
     TCP/UDP 53, 88, 3389, 389, 443, 445, 636, 3268, 3269
    Am I right in thinking that in order for my DA clients to reach file shares (for example) I need to ensure that the required protocol and ports are open between my DA server and my file share (i.e. 443)? Doesn't this open a whole load of security holes?
    Thanks
    IT Support/Everything

    Hi there - in a similar scenario on many customer sites i have done the following configurations on the Internal Firewalls
    Internal IP of the DA Server ---> allow all traffic to selected VLAN's
    The above rule is restricting traffic from the DA Server to the required VLAN's / Networks you specify, The reasoning being is that Direct Access requires full connectivity to your apps / infrastructure. 
    john davies

  • Open ports needed for remote hd login

    what ports should i have open to remotely connect to my AEBS external hard drive??

    The following worked for me to access my airdisk via inet
    1: Set the AE to bridging modus
    2: If you have a firewall active, you have to forward port TCP 548 (afp) to the internal IP address of your AE. You can see the IP in the main screen of the airport utility program. It has the format 192.168.1.xx or 10.1.1.xx.
    3: Figure out your external ip address -There's widgets that do that, e.g. iStat Nano-
    You can access the airdisk as follows:
    Open finder
    Press command-k or select 'Connect to server' from the 'Go' menu.
    Type afp://external ip/name of your airdisk
    example: afp://86.354.32.45/MyDisk
    And click connect.
    Note: You must be connected to the inet from another location than yours, otherwise it won't connect.
    That's it
    Marc

  • Ports needed for a nfs client

    Hello -
    Which ports on a firewall running on a solaris 10 machine should I open to make it a nfs client? I openned udp/tcp port 111. But it didn't work. The file server is running solaris 9.
    Thanks
    Rui

    If you use the WebNFS feature of Solaris it will only require port 2049, to use WebNFS, simply mount your NFS share as an URI.
    For example, replace:
    mount server:/share /mountpoint
    with
    mount nfs://server/share /mountpoint
    .. to use WebNFS instead.
    .7/M.

  • Firewall Port Number for Itunes?????

    Can anyone tell me what port number Itunes communicates through?

    Thanks for the numbers. We have a corporate firewall that is really locked down tight and of course the suit types don't really want me to blow any holes in their so called iron wall...but I keep getting requests for itunes radio, so I guess I'll just have to shake the tree a little and see what falls out!
    Thanks again.

Maybe you are looking for