I get a lot of scan errors relating to permissions or firewall issues. the windows firewall is enabled on the workstations. I read up on how to make the scan work and the one item i have concern about is opening ports 1024 - 2000 for dynamic WMI. I would have to open up each of the 997 ports one entry at a time in the firewall port exception list. Is there any other way to accomplish this task? Creating 997 individual port exception entries does not seem like the correct way to solve this problem.

2 Spice ups

You should be able to enable the exception for Remote administration in your GPO for the firewall.

Yes, on the clients make sure remote administration is enabled, and WMI will use ports TCP 135 and TCP 445.

For a more detailed explanation:

http://community.spiceworks.com/education/projects/Windows_Firewall

done that already, no help. when I disable the windows firewall GPO and the firewall shuts off on the workstation the scan works no errors but i need to have the scan work with the firewall on.

That’s very odd, are you blocking outgoing from the machine traffic too? Maybe that needs to be removed.

FOUND IT! under a close inspection of the GPO the scope was incorrectly applied missing a lot of machines. Machines with scan errors. :slight_smile:

Fixed I should not see many r any scan errors tomorrow.