What Specific Firewall Rules are Needed for the DPM Server?

Hello,
We want to confirm which firewall ports need to be opened on the DPM server (not protected servers) for all DPM processes, so that we can set these rules in group policy. Below are what we
think are the needed rules. Note that we have rules for both new DPM 2012 installs and upgrades from DPM 2010 to 2012, since these use different program paths.
Rule Name
Program Path
Protocol
Local Port
DPM 2012 DCOM Port
Any
TCP
135
DPM 2012 AM Port
Any
TCP
6075
DPM 2012 RTM Agent Coordinator
C:\Windows\Microsoft Data Protection Manager\DPM\ProtectionAgents\AC\4.0.1908.0\dpmac.exe
Any
Any
DPM 2012 SP1 Agent Coordinator
C:\Windows\Microsoft Data Protection Manager\DPM\ProtectionAgents\AC\4.1.3313.0\dpmac.exe
Any
Any
DPM 2012 R2 Agent Coordinator
C:\Windows\Microsoft Data Protection Manager\DPM\ProtectionAgents\AC\4.2.1205.0\dpmac.exe
Any
Any
DPM 2012 AM Service Host (New Install
%ProgramFiles%\Microsoft System Center 2012\DPM\DPM\bin\AMSvcHost.exe
Any
Any
DPM 2012 AM Service Host (Upgrade Install)
%ProgramFiles%\Microsoft DPM\DPM\bin\AMSvcHost.exe
Any
Any
DPM 2012 DPM AM Service (New Install)
%ProgramFiles%\Microsoft System Center 2012\DPM\DPM\bin\DPMAMService.exe
Any
Any
DPM 2012 DPM AM Service (Upgrade Install)
%ProgramFiles%\Microsoft DPM\DPM\bin\DPMAMService.exe
Any
Any
DPM 2012 MSDPM (New Install)
%ProgramFiles%\Microsoft System Center 2012\DPM\DPM\bin\msdpm.exe
Any
Any
DPM 2012 MSDPM (Upgrade Install)
%ProgramFiles%\Microsoft DPM\DPM\bin\msdpm.exe
Any
Any
DPM 2012 DPMRA (New Install)
%ProgramFiles%\Microsoft System Center 2012\DPM\DPM\bin\DPMRA.exe
Any
Any
DPM 2012 DPMRA (Upgrade Install)
%ProgramFiles%\Microsoft DPM\DPM\bin\DPMRA.exe
Any
Any
Questions:
Are any of these rules not needed?
We know the Agent Coordinator rules are needed on protected servers. Are they also needed on the DPM server (including if we use secondary DPM servers)?
The DPM Configuring Firewalls TechNet page says DCOM uses TCP 135 and the RPC Dynamic ports. Does that mean we also need a rule that opens all TCP RPC Dynamic ports for
any program? Or is this not necessary since we have rules for msdpm.exe and dpmra.exe? Reference:
http://technet.microsoft.com/en-us/library/hh757794
What other rules may be missing, if any?
Note that we do not include rules for ports 53 (DNS), 88 (Kerberos), 389 (LDAP), 137-139 & 445 (NetBIOS) because we already open these ports in other group policy objects.
Also, the below forums post says two exceptions for SQL Server are needed on the DPM server to allow the Remote Administrator console to work. Is there any documentation in the DPM TechNet site on these rules?
http://social.technet.microsoft.com/Forums/en-US/aa88fd00-6836-46d3-8a93-edb487109118/dpm-2012-remote-administration?forum=dataprotectionmanager
Thanks,
-Taylorbox

Does anyone have any comments on this post? We would especially appreciate some input from Microsoft reps to help us ensure we're setting up the correct firewall rules.
Thanks,
-Taylorbox

Similar Messages

  • What AC adapter do I need for the Sat Pro A30?

    What AC adapter do i need for the Satellite pro A30, it will not charge and as it has a loose connection on the plug.

    Hi,
    in the specs I found this:
    up to CPU 2.8GHz PA3165U/E-1ACA Autosensing AC Adaptor - 0.52kg - 90W - 100~240V 50/60Hz (Universal) - DC 19V 4.74A -- over 2.8GHz PA3290U 120W
    Bye

  • What SSL certificates needed for the FTP server

    Hi,
    I want to create certificate fot the FTP server is there any specific format for the FTP server. what i have to create for Secure communication.
    plz tell me in detail.
    Thanks
    Ravi

    Does anyone have any comments on this post? We would especially appreciate some input from Microsoft reps to help us ensure we're setting up the correct firewall rules.
    Thanks,
    -Taylorbox

  • What anti-theft solutions are best for the ipad?

    Hello,
         I would like to know which anti-theft solutions are best for the IPad. I am ordering several for work and I would like to know. Thanks.

    It depends upon how far you are willing to go.  Keeping it locked in a bank vault comes to mind but I suppose you want more flexibility.  Are you talking about physical attachment or just something to discourage a thief, or something to protect data integrity in case of theft? Realize that in many situations somebody may steal something and only later check if it has any value.  If it doesn't they will toss it in the nearest river, but you've still lost it.  As for iPads, a thief can reset one and it's like new.
    Find My iPad - http://www.apple.com/ipad/icloud/#find - has to be enabled before device is lost.  It also requires the device be on and connected to registered WiFi network or data service, and not having been restored by the finder (if it was really stolen then the thief has probably restored it).  If you have activated the "Find My" feature, go to https://www.icloud.com or use the Find My iPhone app - http://itunes.apple.com/us/app/find-my-iphone/id376101648?mt=8
    Setting up iCloud (requires iOS5) - http://www.apple.com/icloud/setup/ios.html - includes activating the 'Find My' feature.
    Kappy's missing idevice recommendations 09/2012 - https://discussions.apple.com/message/19569712

  • What antivirus protection do I need for the iPad?

    I am seeing some unusual activity after receiving an email.  What antivirus protection should we be considering for the ipad2?

    None - there are no viruses for the iPad (or iPhone or iPod Touch), and therefore there are no antivirus apps available in the iTunes App Store

  • What screw size do I need for the HDD data cable in 15" MBP (mid-2010)?

    In what turned out to be the most frustrating night of my life, I decided to upgrade my mid-2010 15" MBP from the factory 256GB HDD to a 1TB drive. All was well until the ultra-cheap internal screws stripped, which I have heard is a big problem. I finally got the mounts out with a little force, and then accidentally tore the HDD data cable.
    So when I tried to unscrew the small screws with precision and care to replace the data cable, those screws ALSO stripped. I managed to get one out, but the other one was stuck, and even the Genius at Apple said they couldn't do anything for me because their methods of extraction could possibly ruin my upper case.
    So I ended up just cutting the rest of the HDD cord around the last remaining stuck screw. I've included a picture below, the screw that remains is the one with the red circle around it.
    So the real question: I lost the other screw, so I have no idea what size it is and if I can buy it from a local hardware or electronics store, or is it something I will need to special order?
    Thanks in advance for your help.
    Signed,
    Screwed by a simple harddrive replacement

    Hey Courcoul, thanks for your response. I saw that they have the screw set, but I want to avoid paying $60 for the whole set when all I need is the two tiny ones. Sure, I could keep the rest as spares, but I think I've learned my lesson about messing with the internals.
    Actually, it's out of stock so I couldn't buy it if I wanted

  • What windows system services are needed for iTunes 12

    I recently installed the update for iTunes on my PC.  Something happened near the end of the process:  a dialog box popped up telling me that some of the Windows services were missing from my computer.  I was given three (3) choices: cancel / retry / ignore.  I first tried retry and that didn't work, so I clicked on the ignore option and the installation finished.
    Now, I think the missing Windows 7 (64-bit) service was the "Apple Mobile Device" Service.  Unfortunately, I failed to write down exactly what the dialog box said, so there could be other services missing from my computer.  And since I have no way to know when the service/s was/were lost a system restore will not work.

    For general advice see Troubleshooting issues with iTunes for Windows updates.
    The steps in the second box are a guide to removing everything related to iTunes and then rebuilding it which is often a good starting point unless the symptoms indicate a more specific approach. Review the other boxes and the list of support documents further down the page in case one of them applies.
    The further information area has direct links to the current and recent builds in case you have problems downloading, need to revert to an older version or want to try the iTunes for Windows (64-bit - for older video cards) release as a workaround for installation or performance issues, or compatibility with QuickTime or third party software.
    Your library should be unaffected by these steps but there are also links to backup and recovery advice should it be needed.
    tt2

  • What megapixel size shots are needed for a calendar?

    I have a Canon that shoots 3.2 megapixel shots, 2048 x 1536, and when I place these in single, double or even triple layout pages I get a yellow exclamation mark and this message over the photo: "This photo may print at too low a quality."
    What size images does Apple expect us to have for their calendar pages? Is there a chart that lists the size of images for all the layouts (single image through to seven images)?
    Do I need a new camera?
    Many thanks, Mike

    Mike:
    I've ordered calendars with photos from a camera with a max pixel size of 1600 x 1200 and was very happy with the results. iPhoto's print warning is set at 140 dip (not sure if it's for ordering prints or items other than books which is 180.
    Do you Twango?
    TIP: For insurance against the iPhoto database corruption that many users have experienced I recommend making a backup copy of the Library6.iPhoto database file and keep it current. If problems crop up where iPhoto suddenly can't see any photos or thinks there are no photos in the library, replacing the working Library6.iPhoto file with the backup will often get the library back. By keeping it current I mean backup after each import and/or any serious editing or work on books, slideshows, calendars, cards, etc. That insures that if a problem pops up and you do need to replace the database file, you'll retain all those efforts. It doesn't take long to make the backup and it's good insurance.
    I've created an Automator workflow application (requires Tiger), iPhoto dB File Backup, that will copy the selected Library6.iPhoto file from your iPhoto Library folder to the Pictures folder, replacing any previous version of it. It's compatible with iPhoto 08 libraries. iPhoto does not have to be closed to run the application, just idle. You can download it at Toad's Cellar. Be sure to read the Read Me pdf file.

  • What games and apps are supported for the N80 and ...

    Looking for some games for my N80 and some apps.
    Where is the best place to find out what is supported?
    Does anyone know what s supported yet? games/apps etc etc?
    My N80 is on Orange purchased in June 2006 firmware v 3.0617.06 03-05-2006
    Cheers
    Andy

    Support is still sporadic at the moment - but the best place I've found is my-symbian.com
    HTH

  • What levels of Acrobat are needed to use forms created in Acrobat Pro 9?

    What levels of Acrobat are needed to use forms created in Acrobat Pro 9? I want to use my form as a job ticket but want to know what levels of adobe reader are needed for the end users to be able to fill out & submit the forms without any problems.

    Reader 7 and higher should be able to fill out forms and submit if the pdf format allows Reader 7 to fill out the form. However, without problems is a different issue. Submission of forms via email is ALWAYS a problem. It is always better to post the form on a website and have the form filled out on the web and have the data stored or sent to a database for further action.

  • What permissions are needed on the client side for RunspaceFactory.CreateRunspace?

    Hi.
    I am running a remote powershell command from an IIS application to an Exchange server getting the below error. Everything works fine if the IIS application pool identity is in the local administrators group on the IIS server so we can rule out issues with
    firewall or anything on the Exchange server. It is a problem with lack of privileges on the local server. 
    So my question is: What permissions are required on the local server for RunspaceFactory.CreateRunspace? I find good documentation on the permissions required on the server side, but nothing about the client side.
    The last Win32 error code after failure is 1008.
    An internal error occurred. 
    at at System.Management.Automation.Remoting.Client.WSManClientSessionTransportManager.Initialize(Uri connectionUri, WSManConnectionInfo connectionInfo) 
    at System.Management.Automation.Remoting.Client.WSManClientSessionTransportManager..ctor(Guid runspacePoolInstanceId, WSManConnectionInfo connectionInfo, PSRemotingCryptoHelper cryptoHelper) 
    at System.Management.Automation.Remoting.ClientRemoteSessionDSHandlerImpl..ctor(ClientRemoteSession session, PSRemotingCryptoHelper cryptoHelper, RunspaceConnectionInfo connectionInfo, URIDirectionReported uriRedirectionHandler) 
    at System.Management.Automation.Remoting.ClientRemoteSessionImpl..ctor(RemoteRunspacePoolInternal rsPool, URIDirectionReported uriRedirectionHandler) 
    at System.Management.Automation.Internal.ClientRunspacePoolDataStructureHandler..ctor(RemoteRunspacePoolInternal clientRunspacePool, TypeTable typeTable) 
    at System.Management.Automation.Runspaces.Internal.RemoteRunspacePoolInternal..ctor(Int32 minRunspaces, Int32 maxRunspaces, TypeTable typeTable, PSHost host, PSPrimitiveDictionary applicationArguments, RunspaceConnectionInfo connectionInfo) 
    at System.Management.Automation.Runspaces.RunspacePool..ctor(Int32 minRunspaces, Int32 maxRunspaces, TypeTable typeTable, PSHost host, PSPrimitiveDictionary applicationArguments, RunspaceConnectionInfo connectionInfo) 
    at System.Management.Automation.Runspaces.RunspaceFactory.CreateRunspacePool(Int32 minRunspaces, Int32 maxRunspaces, RunspaceConnectionInfo connectionInfo, PSHost host, TypeTable typeTable, PSPrimitiveDictionary applicationArguments) 
    at System.Management.Automation.RemoteRunspace..ctor(TypeTable typeTable, RunspaceConnectionInfo connectionInfo, PSHost host, PSPrimitiveDictionary applicationArguments) 
    at System.Management.Automation.Runspaces.RunspaceFactory.CreateRunspace(RunspaceConnectionInfo connectionInfo, PSHost host, TypeTable typeTable, PSPrimitiveDictionary applicationArguments) 
    at System.Management.Automation.Runspaces.RunspaceFactory.CreateRunspace(RunspaceConnectionInfo connectionInfo) 

    Thanks Daniel.
    I see that the IIS server has a GPO setting 'Allow log on locally' to the local administrators group for this server. I will order add of the IIS app pool identity to this list.
    I tried the process monitor comparing runs with and without the app pool identity as local administrator. The runs are identical up to the point where one does something useful and the other closes 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN'.
    There are no failures.
    I am not using my runspace objects for multiple threads. I dispose after use.
    I will end up with the below if I change. Comments?
    public static PowershellResult RunPowerShellCommandExchange2010(string exchangeServer, string command, ICollection<KeyValuePair<string, object>> parameters, string usr, string pwd) {
    WindowsImpersonationContext impersonationContext = null;
    try {
    impersonationContext = WindowsIdentity.Impersonate(IntPtr.Zero);
    GetProcessInformation();
    try {
    var connectionInfo = GetExchange2010ConnectionInfo(exchangeServer, usr, pwd);
    using (var runspace = RunspaceFactory.CreateRunspacePool(1, 1, connectionInfo)) {
    using (PowerShell powershell = PowerShell.Create()) {
    var psCommand = new PSCommand();
    if (parameters != null) {
    psCommand.AddCommand(command);
    foreach (KeyValuePair<string, object> parameter in parameters) {
    if (parameter.Value == null) psCommand.AddParameter(parameter.Key);
    else psCommand.AddParameter(parameter.Key, parameter.Value);
    } else {
    //if parameters argument is null the command will be treated as script
    psCommand.AddCommand(new Command(command, true));
    powershell.Commands = psCommand;
    runspace.Open();
    powershell.RunspacePool = runspace;
    var resultPSObjects = powershell.Invoke();
    var psResult = new PowershellResult {
    PSObjects = resultPSObjects,
    Errors = powershell.Streams.Error.ToList()
    return psResult;
    } catch (Exception ex) {
    var windowsIdentity = WindowsIdentity.GetCurrent();
    int errorCode = Marshal.GetLastWin32Error();
    if (windowsIdentity != null) throw new Exception(string.Format("Failed to run Exchange powershell command '{0}' as user {1} passing executing user {2} due to: {3} at {4}. Server: {5}. Last error code: {6}", command, windowsIdentity.Name, usr, ex.Message, ex.StackTrace, exchangeServer, errorCode), ex);
    throw new Exception(string.Format("Failed to run Exchange powershell command '{0}' as unknown user passing executing user {1} due to: {2} at {3}. Server: {4}. Last error code: {5}", command, usr, ex.Message, ex.StackTrace, exchangeServer, errorCode), ex);
    } finally {
    if (impersonationContext != null) {
    impersonationContext.Undo();
    Tore Olav Kristiansen

  • "iTunes has encountered a problem and needs to close. We are sorry for the

    HI all
    I've got know this problem:
    ""iTunes has encountered a problem and needs to close. We are sorry for the inconvenience." With the option to send error report or don't send.
    and the error signature is:AppName: itunes.exe AppVer: 7.0.2.16 ModName: unknown
    ModVer: 0.0.0.0 Offset: 01a21040
    Does anyone know what should i do?
    Thanks
    Wouiners

    I had the same issue. I found a solution under a different thread posted by scubastevee32. It worked for me. I copied pasted his solution below.
    after countless hours of dead ends.... I found this to fix the problem(thank you "b noir")
    hat one could be being caused by a problem with your QuickTime. (itunes uses QuickTime for audio and video playback.)
    so let's try swapping out your QuickTime.
    head into your Add/Remove programs. uninstall QuickTime.
    Next, we’ll manually remove any leftover program files and folders.
    1. On the Start menu, click My Computer (or double-click My Computer on the Desktop).
    2. In My Computer, open Local Disk.
    3. Open Program Files.
    4. Right-click on the QuickTime folder and click Delete from the shortcut menu.
    5. Navigate to C:\Windows\system32\.
    6. Remove the files QuickTime.qts and QuicktimeVR.qtx.
    7. Restart your computer.
    next, we'll get a fresh copy of QuickTime into your PC by doing a repair install of itunes.
    switch off antivirus and antispyware applications prior to the repair install.
    go into Add/Remove and select itunes. click "Change" and then click "Repair".
    if the repair install goes through okay, restart the PC and try launching itunes again. does it launch properly now?
    HP Pavilion   Windows XP Pro  

  • What technical components are needed for integration of SAP BI and BO?

    Hello,
    What technical components are needed for integration of SAP BI and BO?

    Hi,
    you need to setup a BOBJ server (eg. BusinessObjects Enterprise XI 3.1 or BO Edge 3.1) and then install the BusinessObjects integration Kit for SAP on the same machine your BOBJ server runs.
    In order to build reports you can either use Crystal Reports (eg Install Crystal Report Designer 2008 V1 if you have an XI 3.1 server installed), WebIntelligence (Install the Business Objects XI 3.1 Client Tools in order to be able to build universes), BusinessObjects Voyager or XCelsius. Please note that you have to always install the BOBJ integration Kit for SAP (should be the same version as your server and client installation) on your clients AFTER you installed one or more of the above client tools.
    Please take again a look at the following link for more detailed information (from Ingo) on this:
    [https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/a00ee3b2-5283-2b10-f1bf-8c6413e0898f]
    Regards,
    Stratos

  • 'NI-PAL Service Manager has encountered a problem and needs to close. We are sorry for the inconvenience.'

    Hello,
    Any idea how to fix this problem that casuses this error?
    'NI-PAL Service Manager has encountered a problem and needs to close. We are sorry for the inconvenience.'
    I have been re-loading LabVIEW 8.0.1 Pro Dev Sytem, NI-DAQ (Traditional) and NI-DAQmx, all day.  This probelm seems to be related to the fact that I can, no longer, create executables or open my .lvproj files, yielding the other error:
    '' Problem sending commands to the program"
    Thank you
    Message Edited by FLT CTRL 6 on 06-02-2006 03:41 PM

    NI-PAL service Manager has encountered a problem and needs to close.… tell Microsoft...10Jan08
    Yesterday I started having this error message pop up when I first boot up my computer.  I haven’t even started LabVIEW. 
    Recent changes:
    6Jan08 Replaced motherboard and CPU.
    6Jan08 Formatted hard drive and reinstalled software(Windows XP Home Edition).  Computer working fine.
    8Jan08 Installed LabVIEW 8.0 Student Edition.  LV is working fine and the message does not appear.
    9Jan08 Download and install NiDAQ 8.6.1.  Reboot the system and the above error shows up.  LabVIEW works fine so far.
    Anybody have any ideas on what the problem is?  I have a screen shot of the actual message, but I can't load it on this page.
    Oliver
    [email protected]

  • Dynamiclinkmanager has encountered a problem and needs to close.  We are sorry for the inconvenience

    I get this message when opening Prem. ele 9 trial. "dynamiclinkmanager has encountered a problem and needs to close.  We are sorry for the inconvenience."
    Prem opens but does not work well. When I load a VOB file it comes in as audio only. Prem. barely works. Any suggestions?
    thanks

    So which issue do you want to deal with?
    With this many problems, it appears that your computer is not set up well to work with this program. I recommend you contact Adobe Tech Support and have them see if they can troubleshoot it. You may need more help than we can give you on this forum. Sorry.
    (It might also help to know what operating system you're working on, of course. Macs have a known issue with the dynamiclinkmanager file, as discussed in this thread: http://forums.adobe.com/thread/634929 )

Maybe you are looking for

  • SQL Expressions missing from field explorer

    Hi SAP, I am using Crystal XI and created a report several months ago.  I want to update the report by using an SQL expression to increase performance.  However, I do not see the SQL Expression available to me in the field explorer just on this parti

  • How to pass class object  as in parameter in call to pl/sql procedure ?

    hi, i have to call pl/sql proecedure through java. In pl/sql procedure as "In" parameter i have created "user defined record type" and i am passing class object as "In" parameter in call to pl/sql procedure. but it is giving error. so, anyone can ple

  • Default font display

    I've just updated my operating system to 10.4.10 from 10.4.6. I manage a website designed by someone else, and they didn't define a font size for body text/paragraphs in our CSS. As a result, in the newest version of Safari, the portion of the site t

  • Uninstall Elements 8? and Elements 11 on 2 computers?

    Do I need to uninstall Photoshop Elements 8 if I am going to install Elements 11? And, can I  put Elements 11 on two of my  computers?

  • Footage differ on mini preview and the viewport window

    god , it's driving me crazy now. already worked on this for 2~3 days... see screenshot http://img231.imageshack.us/img231/6770/damnki3.jpg http://img231.imageshack.us/img231/3682/avirx8.jpg I scanned all the old photos of my family, around 5xx pics o