Page History
...
The following links provide additional information about how to troubleshoot WMI connectivity issues:
.Newtablink alias Securing a remote WMI Connection url http://msdn.microsoft.com/en-us/library/windows/desktop/aa393266(v=vs.85).aspx
.Newtablink alias Help with Scripts url http://www.microsoft.com/technet/scriptcenter/topics/help/wmi.mspx
Using WbemTest (Windows Management Instrumentation Tester)
You can use the
Newtablink | ||||
---|---|---|---|---|
|
To use WbemTest:
- Run wbemtest.exe.
- Click Connect.
- In the NameSpace text box, enter
\\server\root\cimv2
whereserver
is the name of the server to which you want to connect. - Click Connect.
- Click Query.
- Enter
select*
from win32_process. - Click Apply.
If WbemTest connects to the remote server and issues the query using WMI, you should see a query result with output. In this case, WMI to the required server is working and no further action is needed. For more information on the Windows Management Instrumentation Tester, refer to the Microsoft document,
Newtablink | ||||
---|---|---|---|---|
|
...
- Make sure that the Remote Procedure Call (RPC) service is running on the remote server.
- Verify that there is a TCP listener on the remote server by running the netstat -nao command and verifying that there is the following entry:
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 1304
. - In the Tools subdirectory, run
rpcping /s
<servername><servername> /t ncacn_ip_tcp
where <servername><servername>
is the name of the remote server. This command verifies that RPC can communicate with the remote server and output similar to:
Completed 1 calls in 15 ms
66 T/S or 15.000 ms/T - Make sure that local or internal network firewalls do not block traffic by either disabling the firewall or configuring the Windows firewall to allow incoming RPC traffic.
- Try to use the remote server IP address instead of the server name. If the IP address works, you may have a DNS issue.
- If the remote server resides in a different domain, the two domains may not trust each other, or the user account does not have administrator permissions on the remote server/domain.
- If both computers are in the same domain, and the user account has administrator permissions, try rejoining both computers to the domain.
...
- If the remote computer is running Windows XP, make sure it is not set to Force Guest. This setting forces impersonation of any connection as Guest.
- Open the Local Security Policy console from Administrative Tools.
- Browse to Security Settings > Local Policies > Security Options.
- Double-click Network Access: Sharing And Security Model For LocalAccounts.
- Change the settings from Guest Only to Classic.
- Make sure DCOM is enabled on the remote server:
- Run DcomCnfg on the remote server.
- Click Component Services.
- Expand Computers.
- Right click My Computer and select Properties.
- Click the Default Properties tab.
- Make sure Enable Distributed COM on this computer is checked.
- Verify the configuration of the correct DCOM remote launch and activation permissions:
- Run DcomCnfg on the remote server.
- Click Component Services.
- Expand Computers.
- Right click My Computer and select Properties.
- Make sure Enable Distributed COM on this computer is checked.
- Click the Com Security tab.
- Under Launch and Activation Permissions, click Edit Limits.
- In the Launch Permissions dialog box, make sure your user account or group is listed in the Groups or user names list. If your user account or group is not listed, click Add and add it to the list.
- In the Launch Permission dialog box, select your user account or group in the Group or user names list. In the Allow column under Permissions for User, select Remote Launch and Remote Activation, and then click OK.
- Make sure the correct DCOM remote access permissions are configured:
- Run DcomCnfg on the remote server.
- Click Component Services.
- Expand Computers.
- Right click My Computer and select Properties.
- Make sure Enable Distributed COM on this computer is checked.
- Click the Com Security tab.
- Under Access Permissions, click Edit Limits.
- In the Access Permission dialog box, select ANONYMOUS LOGON name in the Group or user names list. In the Allow column underPermissions for User, select Remote Access, and then click OK.
- Make sure the correct WMI namespace permissions are configured.
- Run wmimgmt.msc.
- Right-click WMI Control, and then select Connect to another computer.
- Enter the remote server name, and then click OK.
- Right-click WMI Control, and then select Properties.
- In the Security tab, select the namespace, and then click Security.
- Locate the appropriate account, and then check Remote Enable in the Permissions list.