Article ID: 885726 - Last Review: September 27, 2007 - Revision: 3.4 The Microsoft Operations Manager 2005 agent does not install on computers that are running Windows XP with Service Pack 2 (SP2) and Windows Server 2003 with Service Pack 1 (SP1)Important This article contains information that shows you how to help lower security settings or how to turn off security features on a computer. You can make these changes to work around a specific problem. Before you make these changes, we recommend that you evaluate the risks that are associated with implementing this workaround in your particular environment. If you implement this workaround, take any appropriate additional steps to help protect your system. On This PageSYMPTOMSWhen you use the Install/Uninstall Agents Wizard to try to install an agent on a computer that is running Microsoft Windows XP with Service Pack 2 (SP2) or Microsoft Windows Server 2003 with Service Pack 1 (SP1), you receive the following error message in the Microsoft Operations Manager (MOM) 2005 Task Progress dialog box: Computer Management Task Summary: 1 Agent install(s) failed. Source: Microsoft Operations Manager
Source: Microsoft Operations Manager
Source: Microsoft Operations Manager
CAUSEThis issue can occur if Windows Firewall is running on the destination computer or on the MOM server computer. If Windows Firewall is running on a MOM server computer, MOM agents cannot communicate with the MOM Server. If Windows Firewall is running on a destination computer, or a potential MOM agent, the MOM server cannot perform a push installation of the agent. By default, Windows XP with SP2 turns on Windows Firewall. By default, Windows Firewall is not turned on in Windows Server 2003 with SP1. TroubleshootingYou can use the MOM Remote Prerequisite Checker (MOMNetChk.exe) utility in the Microsoft Operations Manager Resource Kit to scan a computer for the status of the ports that the MOM service and related services use. To obtain the MOM Resource Kit, visit the following Microsoft Web site:http://technet.microsoft.com/en-us/opsmgr/bb498240.aspx
(http://technet.microsoft.com/en-us/opsmgr/bb498240.aspx)
The MOM Remote Prerequisite Checker conducts a series of connectivity tests. These tests include a ping test and a test for DNS connectivity. The utility also provides information about the status of services that the MOM service depends on. This information can appear in a report window or be saved in the Momscan.log file. To use the MOM Remote Prerequisite Checker, start MOMNetChk.exe, enter the computer name, and then click Run Scan. If you want to save the results to a log file, click Save to Log File, and then specify the location of the file. To view the results of the tests that were run, expand the nodes in the left pane of the utility window. Note The MOMNetChk.exe utility tests the status of required network and service components. It does not report specific errors. WORKAROUNDWarning This workaround may make your computer or your network more vulnerable to attack by malicious users or by malicious software such as viruses. We do not recommend this workaround but are providing this information so that you can implement this workaround at your own discretion. Use this workaround at your own risk. To work around this issue, manually install the agent, or configure Windows Firewall to let the MOM 2005 server communicate with the agent computer. Manually install the agentTo manually install the agent, follow these steps:
Configure Windows FirewallImportant These steps may increase your security risk. These steps may also make your computer or your network more vulnerable to attack by malicious users or by malicious software such as viruses. We recommend the process that this article describes to enable programs to operate as they are designed to, or to implement specific program capabilities. Before you make these changes, we recommend that you evaluate the risks that are associated with implementing this process in your particular environment. If you choose to implement this process, take any appropriate additional steps to help protect your system. We recommend that you use this process only if you really require this process.To configure the Windows Firewall to let the MOM 2005 server communicate with the agent computer, you must open ports and then enable a program. On computers that are running Windows Server 2003 with SP1, we recommend that you use the new Security Configuration Wizard to configure Windows Firewall for MOM 2005. Open portsTo open the ports when Windows Firewall is running on the MOM server, follow these steps:
Open ports and enable a programTo open the ports, and to enable a program when Windows Firewall is running on the destination agent computer, follow these steps:Important This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base: 322756
(http://support.microsoft.com/kb/322756/
)
How to back up and restore the registry in Windows
If the MOM server computer and the MOM agent computer are not on the same subnet, you must configure the Scope setting for each exception to Any computer. If the MOM server computer and the MOM agent computer are not on the same subnet, and the Scope setting is set to Subnet only, Windows Firewall will block communication. If all the MOM components are on the same subnet, restrict network access even more by configuring the Scope setting to Subnet only to additionally restrict network access.
| Article Translations
|
Back to the top
