User`s guide
Table Of Contents
- Application Discovery Manager User’s Guide
- Contents
- About This Book
- Architecture Overview
- Getting Started
- Managing ADM
- Groups
- Discovery
- Application Patterns
- Report
- Connectors
- Solver
- Index
VMware, Inc. 41
Chapter 5 Discovery
WMI Deployment Recommendations
FollowingaretheWMIdeploymentrecommendations.
Creating a User for WMI Detail Discovery
UsingWMItoqueryremotehostsfortheirconfigurationdetailsrequiresappropriateprivileges,asdescribed
next.Toeasilymanagetheseprivileges,itisrecommendedtouseaseparatedomainuserforthispurpose.
Therefore,thefirststepindeployingWMIDetailDiscoveryistocreate
adomainuseraccount.Thisuser
shouldnothaveanyspecialadministrativeprivileges.Infact,thereisnoreasonforittobelongtoanygroups
atall.
Intheeventthatalocaladministratoruserisusedinsteadofaspeciallycreateduser,itisimportantthat
DCOMconfigurationallows
remoteaccessandlaunchforadministratorusers.Troubleshootingtipsregarding
WMIandDCOMpermissionsisfoundinthearticleat:
http://blogs.technet.com/askperf/archive/2007/08/14/wmi-troubleshooting-permissions.aspx
YouneedtocreateaprofileandtemporaryfolderonallmachineswhereDetailDiscoveryistobeperformed
byloggingintothosemachines.
Ifalocaluserisusedratherthanadomainuser,followtheinstructionsin“ConfiguringtheWindowsTelnet
server”onpage 44regardinglocalsecuritypolicy
settings.
Firewall Settings
WMIqueriesinvolvetheMicrosoftRPCnetworkprotocol,whichusesdynamicallyassignedportsonthe
serversideandmightresultinfirewall‐relatedproblems.Toavoidfirewallproblems,youcandeploythe
Collectorapplianceinthesamenetworkasthemanagedhostswithoutafirewallbetweenthem.
Ifyour
environmentrequiresafirewallbetweentheAggregatorapplianceandtheCollectorappliance,
configureittoallowRPCtraffic.Thisisdoneintwostages:
1ConfigurethemanagedhoststouseanarrowrangeofdynamicportsfortheirRPC.Formore
information,gotohttp://support.microsoft.com/kb/154596
2Inthefirewallsettings,openTCP
port135(theportforRPCServiceControlManager)foraccessbythe
Collectorappliance.
Disabling Internal Firewall for Windows XP Service Pack 2
Theinternalfirewallshouldbeturnedofforpartiallydisabledtoallowdirectconnectiontothelocalnetwork.
To change the firewall configuration
1GotoControlPanel>SecurityCenter>WindowsFirewall.
2Tofullydisablethefirewall,in
theGeneraltab,selectOff.
3IfyouwanttoleavethefirewallenabledbutstillallowRPC/DCOMcommunication,selectOninthe
Generaltab,andintheAdvancedtab,clearlocalnetwork.
Setting DCOM Privileges
Inthefollowingsteps,itisassumedthatthedomainnameisMYDOMAINandthattheuserused
forWMI
DetailDiscoveryandthatdomainisnamedDOMAINUSER.
SinceWMIaccesstoaWindowshostinvolv esDCOMtechnology,theDOMAINUSERneedstobeallowedto
performDCOMoperationsoneachmanagedhost.ThisisalreadythedefaultsettinginmostWindowsservers
(Windows2000and2003serverfamilies),butnotinWindowsXPorinserversthathadtheir
defaultschanged.
IMPORTANTWindowsXPwithServicePack2hasabuilt‐ininternalfirewallthatmightblockincoming
RPC/DCOMrequests.