I cannot get the inventory scan to work on a machine that is a member of an OU with Windows Firewall enabled. I have followed the documentation to open ports TCP 135 and 445 and UDP 137. If I disable the firewall, the scan works just fine. Disabling the firewall for every machine is not an option. Are they any other ports that I am missing? Please advise. Thanks in advance!<\/p>","upvoteCount":1,"answerCount":14,"datePublished":"2014-01-10T12:59:55.000Z","author":{"@type":"Person","name":"lee7246","url":"https://community.spiceworks.com/u/lee7246"},"acceptedAnswer":{"@type":"Answer","text":"
You da man. It was a policy conflict with an old gpo that I didn’t even realize existed. Working now! Thank you very much.<\/p>\n
Cheers!<\/p>","upvoteCount":0,"datePublished":"2014-01-15T20:07:24.000Z","url":"https://community.spiceworks.com/t/windows-firewall-via-gpo-an-inventory-scan-failing/267849/11","author":{"@type":"Person","name":"lee7246","url":"https://community.spiceworks.com/u/lee7246"}},"suggestedAnswer":[{"@type":"Answer","text":"
I cannot get the inventory scan to work on a machine that is a member of an OU with Windows Firewall enabled. I have followed the documentation to open ports TCP 135 and 445 and UDP 137. If I disable the firewall, the scan works just fine. Disabling the firewall for every machine is not an option. Are they any other ports that I am missing? Please advise. Thanks in advance!<\/p>","upvoteCount":1,"datePublished":"2014-01-10T12:59:56.000Z","url":"https://community.spiceworks.com/t/windows-firewall-via-gpo-an-inventory-scan-failing/267849/1","author":{"@type":"Person","name":"lee7246","url":"https://community.spiceworks.com/u/lee7246"}},{"@type":"Answer","text":"
You’ll need to also allow ICMP, WMI, and remote management. See here: http://community.spiceworks.com/help/Is_My_Firewall_Software_Getting_In_The_Way%3F<\/a><\/p>","upvoteCount":0,"datePublished":"2014-01-10T13:59:20.000Z","url":"https://community.spiceworks.com/t/windows-firewall-via-gpo-an-inventory-scan-failing/267849/2","author":{"@type":"Person","name":"bryandoe","url":"https://community.spiceworks.com/u/bryandoe"}},{"@type":"Answer","text":" I have enabled both Windows Firewall: Allow remote administration exception and Windows Firewall: Allow ICMP exceptions but it still is not working. What an i missing? Thx<\/p>","upvoteCount":0,"datePublished":"2014-01-10T14:07:51.000Z","url":"https://community.spiceworks.com/t/windows-firewall-via-gpo-an-inventory-scan-failing/267849/3","author":{"@type":"Person","name":"lee7246","url":"https://community.spiceworks.com/u/lee7246"}},{"@type":"Answer","text":" Firewall is still blocking the inventory scan. Do I have to explicitly define open ports in gpo?<\/p>","upvoteCount":0,"datePublished":"2014-01-14T11:34:39.000Z","url":"https://community.spiceworks.com/t/windows-firewall-via-gpo-an-inventory-scan-failing/267849/4","author":{"@type":"Person","name":"lee7246","url":"https://community.spiceworks.com/u/lee7246"}},{"@type":"Answer","text":" Hi findaway, could you try this test command (wmic) and let us know what the error message is?<\/p>\n http://community.spiceworks.com/help/Resolving_Unknown_Devices#Windows<\/a><\/p>","upvoteCount":0,"datePublished":"2014-01-14T18:35:07.000Z","url":"https://community.spiceworks.com/t/windows-firewall-via-gpo-an-inventory-scan-failing/267849/5","author":{"@type":"Person","name":"Ben-B-Spiceworks","url":"https://community.spiceworks.com/u/Ben-B-Spiceworks"}},{"@type":"Answer","text":" Thank you for the response. I am getting the following:<\/p>\n ERROR: It it possible that UAC on Windows 7 is the culprit. Can that be disabled via a gpo?<\/p>","upvoteCount":0,"datePublished":"2014-01-15T14:06:38.000Z","url":"https://community.spiceworks.com/t/windows-firewall-via-gpo-an-inventory-scan-failing/267849/7","author":{"@type":"Person","name":"lee7246","url":"https://community.spiceworks.com/u/lee7246"}},{"@type":"Answer","text":" This error message typically means either:<\/p>\n Did you test with both hostname and IP address, same issue? It might sound strange, but could you test all three of these with the WMIC? For example, let’s say the device info is: [reception-pc], [192.168.1.25]<\/p>\n Test these values for “node”:<\/p>\n Notice the second one has a trailing period after the IP address. If you’re curious more on that here<\/a> (under the comments section).<\/p>","upvoteCount":0,"datePublished":"2014-01-15T18:15:56.000Z","url":"https://community.spiceworks.com/t/windows-firewall-via-gpo-an-inventory-scan-failing/267849/8","author":{"@type":"Person","name":"Ben-B-Spiceworks","url":"https://community.spiceworks.com/u/Ben-B-Spiceworks"}},{"@type":"Answer","text":" same all 3 - rpc service unavailable<\/p>\n if I turn off the firewall, it will work!<\/p>\n I have followed the documentation and double-checked, yet still the same issue.<\/p>\n I have an audit software product on the same box that I am demoing and it works no problem w/ the firewall enabled<\/p>\n Cannot figure this one out???<\/p>\n Thx for your assistance!<\/p>","upvoteCount":0,"datePublished":"2014-01-15T19:51:07.000Z","url":"https://community.spiceworks.com/t/windows-firewall-via-gpo-an-inventory-scan-failing/267849/9","author":{"@type":"Person","name":"lee7246","url":"https://community.spiceworks.com/u/lee7246"}},{"@type":"Answer","text":" Thanks for testing that out - it sounds like the GP isn’t applying, if you can disable the firewall and the WMIC works properly.<\/p>\n Could you try RSoP to confirm GP is applied properly?<\/p>\n
\nDescription = The RPC server is unavailable.<\/p>","upvoteCount":0,"datePublished":"2014-01-15T13:43:03.000Z","url":"https://community.spiceworks.com/t/windows-firewall-via-gpo-an-inventory-scan-failing/267849/6","author":{"@type":"Person","name":"lee7246","url":"https://community.spiceworks.com/u/lee7246"}},{"@type":"Answer","text":"\n
\n