Hi All,
Not sure if this is the correct place or not, feel free to suggest somewhere
better.
I have a number of sites running different subnets, joined togethor via
VPNs.
I have set group policies:
Computer Configuration/Administrative Templates/Network/Network
Connections/Windows Firewall/Domain Profile
-Windows Firewall: Allow inbound file and printer sharing exception: enabled
from *
-Windows Firewall: Allow inbound Remote Desktop exceptions: enabled from *
-Windows Firewall: Allow local port exceptions: enabled
-Windows Firewall: Allow local program exceptions: enabled
-Windows Firewall: Define inbound port exceptions: enabled
--135:TCP:*:Enabled:Offer Remote Assistance
Windows Firewall: Define inbound program exceptions: enabled
--%WINDIR%\PCHealth\HelpCtr\Binaries\Helpctr.exe:*:E nabled:Remote
Assistance - Windows Messenger and Voice
--%WINDIR%\PCHealth\HelpCtr\Binaries\Helpsvc.exe:*:E nabled:Offer Remote
Assistance
--%WINDIR%\system32\msra.exe:*:Enabled:Remote Assistance GUI
--%WINDIR%\SYSTEM32\Sessmgr.exe:*:Enabled:Remote Assistance
-Windows Firewall: Protect all network connections: enabled
Currently I am unable to offer remote assistance to users in other
sites/subnets. At each location, I can offer remote assistance to other
users in that subnet.
I am able to connect via RDP to users in any sites without any issues.
The "Offer remote assistance" fails when trying to "get the logged in
user..."
Anyone have any ideas on what I can change in the firewall GPO to allow this
to work?
|