SCCM Client Install - GPO - Procedure
Configure firewall rule in GPO to allow ports that are obligatory for SCCM client installation. Jotted below is the procedure.
- File and Printer Sharing Service - Allow Both Inbound and Outbound Rule
- Windows Management Instrumentation - Allow only Inbound Rule
- SCCM Remote Control - Allow the port 2701 only for Domain Profile in Inbound Only
- SCCM Client Notification - Allow the port 10123 only for Domain Profile in Inbound Only
Steps to be performed in GPO:
- Open GP management. Right click Domain and create a GPO.
- Specify a name to this policy such as SCCM Client Push Policy. Click OK. Right click the SCCM Client Push policy and click Edit.
- Expand computer configuration, Windows settings, Security settings, Windows firewall with advanced security.
- Right click Inbound Rule and select New Rule. Select Predefined and select File and Printer Sharing from the list. Click Next.
- Select all Rules. Click Next.
- Check the radio button Allow the Connection and click Finish.Our Inbound Rule is created.
- Create Outbound Rule – File and Printer Sharing Service
- Now we will create an outbound rule for the same.Make sure all the rules are selected. Click Next.
- Select Allow the Connection. Click Finish.
- Create Inbound Outbound Rule – Windows Management Instrumentation
- Create an inbound rule selecting Windows Management Instrumentation from predefined. Click Next. Check all the rules and click Next.
- Allow the connection. Click Next.
- Then Create a inbound rule to allow the port 2701 only for domain Profile
- Then Create a outbound rule to allow the port 10123 only for domain Profile