Discussion:
how many DCOM ports are required for agent to MOM communication?
(too old to reply)
Jeffrey
2006-09-07 19:28:02 UTC
Permalink
We need to install agents on about 100 servers across several firewalled
subnets. We opened up all ports from the MOM server to the target subnets,
but don't want to open up all ports from the targets to the agents.
We'd like to push the agent from the server and we expect to update the
agents periodically, so opening just port # 1270 is insufficient. We're
prepared to open a range of dynamic ports per MS KB 154596. My question is
how big a range?
The MS KB suggests a minimum of 100 ports. Is that sufficient for MOM? Is
that 100 ports per MOM agent (that would be 10,000 ports which seems rather
silly).

We're not inclined to do agentless monitoring (we already have an agentless
monitoring product, we'd still need a MOM agent in each subnet and ports
opened from each subnet).

Has anybody had success doing this? Thanks very much for your help.
Jeffrey
2006-09-07 23:28:02 UTC
Permalink
The question restated:

If 100 managed servers use restricted DCOM ports, can they share the same
port range -- can the MOM server use a DCOM port once per MOM agent, or can
it use each DCOM port only once?

It seems unmanageable to configure each agent server with a different port
range and different firewall rules.
Post by Jeffrey
We need to install agents on about 100 servers across several firewalled
subnets. We opened up all ports from the MOM server to the target subnets,
but don't want to open up all ports from the targets to the agents.
We'd like to push the agent from the server and we expect to update the
agents periodically, so opening just port # 1270 is insufficient. We're
prepared to open a range of dynamic ports per MS KB 154596. My question is
how big a range?
The MS KB suggests a minimum of 100 ports. Is that sufficient for MOM? Is
that 100 ports per MOM agent (that would be 10,000 ports which seems rather
silly).
We're not inclined to do agentless monitoring (we already have an agentless
monitoring product, we'd still need a MOM agent in each subnet and ports
opened from each subnet).
Has anybody had success doing this? Thanks very much for your help.
Loading...