I have a small shop, around 25 WinXP SP3 clients, with a Win2008 domain controller. I’ve tried pretty much everything I can find in the community forums.<\/p>\n
According to this page<\/a> I’ve set the following Group Policy:<\/p>\n
Computer Configuration/Administrative Templates/Network/Network Connections/Windows Firewall/Domain Profile:<\/em><\/p>\n Windows Firewall: Allow [incoming] remote administration exception<\/em><\/p>\n For good measure I’ve also set the following GP:<\/p>\n Windows Settings/Security Settings/Windows Firewall with Advanced Security/LDAP/Inbound Rules:<\/em> My DNS tables look clean for all machines.<\/p>\n I have even tried running the line command to allow WMI on a local machine (something I am loath to do - I set up the domain so I could manage computers en masse rather than tweaking settings at each one):<\/p>\n c:> netsh firewall set service remoteadmin enable<\/em><\/p>\n That made no difference either.<\/p>\n What the h*** might be going on here? I’ve spent time on and off for months trying to get this to work and I’ve long since gone past the time when I could have compiled, on paper, the inventory data and other management information I need to have. And yet I soldier on. If I don’t find a solution by the end of April this has become a deal-breaker for me. I absolutely love the idea of the software and the community behind it but - gaaaaaah!<\/p>","upvoteCount":1,"answerCount":16,"datePublished":"2009-04-07T10:38:47.000Z","author":{"@type":"Person","name":"josepherhard-hudson6363","url":"https://community.spiceworks.com/u/josepherhard-hudson6363"},"acceptedAnswer":{"@type":"Answer","text":" Almost got it completely fixed (yay!) using some ideas from other sources as well as the forums here, but things got complicated and I’m not sure precisely which factor was key, or if it was all of them together. I’m going to work on breaking it again and will report back.<\/p>\n I’m at least sure it wasn’t<\/em> the AV. That remained unchanged, and I can now talk to nearly every machine in the domain.<\/p>","upvoteCount":0,"datePublished":"2009-04-17T16:31:07.000Z","url":"https://community.spiceworks.com/t/wmi-scan-problems-this-is-driving-me-nuts/21582/15","author":{"@type":"Person","name":"josepherhard-hudson6363","url":"https://community.spiceworks.com/u/josepherhard-hudson6363"}},"suggestedAnswer":[{"@type":"Answer","text":" I have a small shop, around 25 WinXP SP3 clients, with a Win2008 domain controller. I’ve tried pretty much everything I can find in the community forums.<\/p>\n According to this page<\/a> I’ve set the following Group Policy:<\/p>\n Computer Configuration/Administrative Templates/Network/Network Connections/Windows Firewall/Domain Profile:<\/em><\/p>\n Windows Firewall: Allow [incoming] remote administration exception<\/em><\/p>\n For good measure I’ve also set the following GP:<\/p>\n Windows Settings/Security Settings/Windows Firewall with Advanced Security/LDAP/Inbound Rules:<\/em> My DNS tables look clean for all machines.<\/p>\n I have even tried running the line command to allow WMI on a local machine (something I am loath to do - I set up the domain so I could manage computers en masse rather than tweaking settings at each one):<\/p>\n c:> netsh firewall set service remoteadmin enable<\/em><\/p>\n That made no difference either.<\/p>\n What the h*** might be going on here? I’ve spent time on and off for months trying to get this to work and I’ve long since gone past the time when I could have compiled, on paper, the inventory data and other management information I need to have. And yet I soldier on. If I don’t find a solution by the end of April this has become a deal-breaker for me. I absolutely love the idea of the software and the community behind it but - gaaaaaah!<\/p>","upvoteCount":1,"datePublished":"2009-04-07T10:38:47.000Z","url":"https://community.spiceworks.com/t/wmi-scan-problems-this-is-driving-me-nuts/21582/1","author":{"@type":"Person","name":"josepherhard-hudson6363","url":"https://community.spiceworks.com/u/josepherhard-hudson6363"}},{"@type":"Answer","text":" What antivirus are you running? Do you have any additional security software installed like Microsoft’s Live OneCare?<\/p>","upvoteCount":0,"datePublished":"2009-04-07T11:05:52.000Z","url":"https://community.spiceworks.com/t/wmi-scan-problems-this-is-driving-me-nuts/21582/2","author":{"@type":"Person","name":"scottalanmiller","url":"https://community.spiceworks.com/u/scottalanmiller"}},{"@type":"Answer","text":" Thanks. I’m running AVG Network Edition (that’s the paid centrally managed one, not the free one). I’ve implemented the following components:<\/p>\n No other third-party firewall, only windows firewall.<\/p>\n No additional security software.<\/p>","upvoteCount":0,"datePublished":"2009-04-07T11:47:01.000Z","url":"https://community.spiceworks.com/t/wmi-scan-problems-this-is-driving-me-nuts/21582/3","author":{"@type":"Person","name":"josepherhard-hudson6363","url":"https://community.spiceworks.com/u/josepherhard-hudson6363"}},{"@type":"Answer","text":" Have you tried connecting with the WMI tool from the SpiceWorks server? That is the best way to go. Don’t test SW until you know that WMI itself is working okay. You can test it really quickly with the snap-in.<\/p>\n There is no chance that you have a physical firewall between these machines, is there?<\/p>","upvoteCount":0,"datePublished":"2009-04-07T11:55:46.000Z","url":"https://community.spiceworks.com/t/wmi-scan-problems-this-is-driving-me-nuts/21582/4","author":{"@type":"Person","name":"scottalanmiller","url":"https://community.spiceworks.com/u/scottalanmiller"}},{"@type":"Answer","text":" No firewall - all on the same physical and logical subnet, no VLANS or anything like that. I can Ping, VNC and Remote Desktop to all of them, from any of them, without routing.<\/p>\n I agree it appears to be a WMI problem and not a SW problem.<\/p>\n I’ve tried the whole c:> wmic /user … get serialnumber<\/em> trick. That one leaves me a little puzzled. If I run it from my domain controller I get valid data back. If I run it from my desktop machine (where I have spiceworks loaded) with exactly the same credentials<\/em> i get error messages.<\/p>\n Another interesting symptom: Go into Computer Management, right click the computer to Remote Connect, choose another machine. I can see everything - event logs, local users and groups, services, etc. - EXCEPT when I go to WMI control, right-click, and choose “Properties” I get:<\/p>\n Failed to connect to \\COMPUTERNAME because “Win32: Access is denied.”<\/em><\/p>\n Again, this test actually succeeds from the domain controller, but not from another machine.<\/p>\n I’m not sure I understand what you mean by the WMI Tool, but I’m all about using it. I really want this to work, I’m just running out of ideas and time to futz with it.<\/p>\n Maybe I could just install SW on my DC, but the stubborn part of me wants to understand what’s going on.<\/p>","upvoteCount":0,"datePublished":"2009-04-07T12:33:23.000Z","url":"https://community.spiceworks.com/t/wmi-scan-problems-this-is-driving-me-nuts/21582/5","author":{"@type":"Person","name":"josepherhard-hudson6363","url":"https://community.spiceworks.com/u/josepherhard-hudson6363"}},{"@type":"Answer","text":" I run my SpiceWorks on my DC. We aren’t big enough to segregate that much (our schedule puts us at 28 servers by midsummer) for SW to have its own machine.<\/p>\n Your problem is truly bizarre. The issue is definitely that WMI connection from your workstation. But I can’t imagine what would cause that.<\/p>","upvoteCount":0,"datePublished":"2009-04-07T12:38:13.000Z","url":"https://community.spiceworks.com/t/wmi-scan-problems-this-is-driving-me-nuts/21582/6","author":{"@type":"Person","name":"scottalanmiller","url":"https://community.spiceworks.com/u/scottalanmiller"}},{"@type":"Answer","text":"
\nWMI (DCOM-In) - Allow - to any local / from any local<\/em>
\nWMI (WMI-In) - Allow - to any local / from any local<\/em><\/p>\n
\nWMI (DCOM-In) - Allow - to any local / from any local<\/em>
\nWMI (WMI-In) - Allow - to any local / from any local<\/em><\/p>\n\n