<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SIM 6.0 thru W2K8 firewall, Certificate xfer. in Server Management - Systems Insight Manager</title>
    <link>https://community.hpe.com/t5/server-management-systems/sim-6-0-thru-w2k8-firewall-certificate-xfer/m-p/5242688#M51936</link>
    <description>&lt;!--!*#--&gt;We have been told to use the windows 2008 firewall and have been succesful until someone deleted the VHD my previous version of SIM was running on. I'm rebuilding from scratch with SIM 6.0. When I discover a new system that has the proper settings the first attempt to connect via the SMH I get this at the bottom of the page:&lt;BR /&gt;&lt;BR /&gt;"Unable to retrieve certificate from management server cmsserver.domain.com"&lt;BR /&gt;&lt;BR /&gt;(I'm using "trust by certificate" Trust Mode.)&lt;BR /&gt;&lt;BR /&gt;If I log on to the SMH and attempt to "Get Certificate Information" I get this error message:&lt;BR /&gt;"Error: Unable to obtain a certificate from server VBxx0999. Verify if the server is reachable and running Insight Manager."&lt;BR /&gt;&lt;BR /&gt;If I turn off the firewall, the certificates exchange and then I can turn on the firewall again and everything else works perfectly.&lt;BR /&gt;&lt;BR /&gt;Current ports open:&lt;BR /&gt;2381 TCP any any&lt;BR /&gt;2381 UDP any any&lt;BR /&gt;161 UDP any any&lt;BR /&gt;161 TCP any any&lt;BR /&gt;22 TCP any any&lt;BR /&gt;22 UDP any any&lt;BR /&gt;2301 TCP any any&lt;BR /&gt;2301 UDP any any&lt;BR /&gt;50000 TCP any any&lt;BR /&gt;50000 UDP any any&lt;BR /&gt;&lt;BR /&gt;What port(s) do I need to open in order for these certificates to be installed into the monitored machines' System Management Homepage???&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Mon, 07 Jun 2010 12:17:12 GMT</pubDate>
    <dc:creator>David Orwig</dc:creator>
    <dc:date>2010-06-07T12:17:12Z</dc:date>
    <item>
      <title>SIM 6.0 thru W2K8 firewall, Certificate xfer.</title>
      <link>https://community.hpe.com/t5/server-management-systems/sim-6-0-thru-w2k8-firewall-certificate-xfer/m-p/5242688#M51936</link>
      <description>&lt;!--!*#--&gt;We have been told to use the windows 2008 firewall and have been succesful until someone deleted the VHD my previous version of SIM was running on. I'm rebuilding from scratch with SIM 6.0. When I discover a new system that has the proper settings the first attempt to connect via the SMH I get this at the bottom of the page:&lt;BR /&gt;&lt;BR /&gt;"Unable to retrieve certificate from management server cmsserver.domain.com"&lt;BR /&gt;&lt;BR /&gt;(I'm using "trust by certificate" Trust Mode.)&lt;BR /&gt;&lt;BR /&gt;If I log on to the SMH and attempt to "Get Certificate Information" I get this error message:&lt;BR /&gt;"Error: Unable to obtain a certificate from server VBxx0999. Verify if the server is reachable and running Insight Manager."&lt;BR /&gt;&lt;BR /&gt;If I turn off the firewall, the certificates exchange and then I can turn on the firewall again and everything else works perfectly.&lt;BR /&gt;&lt;BR /&gt;Current ports open:&lt;BR /&gt;2381 TCP any any&lt;BR /&gt;2381 UDP any any&lt;BR /&gt;161 UDP any any&lt;BR /&gt;161 TCP any any&lt;BR /&gt;22 TCP any any&lt;BR /&gt;22 UDP any any&lt;BR /&gt;2301 TCP any any&lt;BR /&gt;2301 UDP any any&lt;BR /&gt;50000 TCP any any&lt;BR /&gt;50000 UDP any any&lt;BR /&gt;&lt;BR /&gt;What port(s) do I need to open in order for these certificates to be installed into the monitored machines' System Management Homepage???&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 07 Jun 2010 12:17:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/sim-6-0-thru-w2k8-firewall-certificate-xfer/m-p/5242688#M51936</guid>
      <dc:creator>David Orwig</dc:creator>
      <dc:date>2010-06-07T12:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: SIM 6.0 thru W2K8 firewall, Certificate xfer.</title>
      <link>https://community.hpe.com/t5/server-management-systems/sim-6-0-thru-w2k8-firewall-certificate-xfer/m-p/5242689#M51937</link>
      <description>P.S. 443 TCP any any is also open</description>
      <pubDate>Mon, 07 Jun 2010 12:32:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/sim-6-0-thru-w2k8-firewall-certificate-xfer/m-p/5242689#M51937</guid>
      <dc:creator>David Orwig</dc:creator>
      <dc:date>2010-06-07T12:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: SIM 6.0 thru W2K8 firewall, Certificate xfer.</title>
      <link>https://community.hpe.com/t5/server-management-systems/sim-6-0-thru-w2k8-firewall-certificate-xfer/m-p/5242690#M51938</link>
      <description>It's port 280 TCP.&lt;BR /&gt;I found this documment for SIM 5 that works. And it shows a lot more than the standard port list that you've seen for years:&lt;BR /&gt;&lt;A href="http://h10018.www1.hp.com/wwsolutions/misc/hpsim-helpfiles/hpsim_5_Security.pdf" target="_blank"&gt;http://h10018.www1.hp.com/wwsolutions/misc/hpsim-helpfiles/hpsim_5_Security.pdf&lt;/A&gt;</description>
      <pubDate>Mon, 07 Jun 2010 12:47:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/sim-6-0-thru-w2k8-firewall-certificate-xfer/m-p/5242690#M51938</guid>
      <dc:creator>David Orwig</dc:creator>
      <dc:date>2010-06-07T12:47:49Z</dc:date>
    </item>
    <item>
      <title>Re: SIM 6.0 thru W2K8 firewall, Certificate xfer.</title>
      <link>https://community.hpe.com/t5/server-management-systems/sim-6-0-thru-w2k8-firewall-certificate-xfer/m-p/5242691#M51939</link>
      <description>It's port 280 TCP.</description>
      <pubDate>Mon, 07 Jun 2010 14:49:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/sim-6-0-thru-w2k8-firewall-certificate-xfer/m-p/5242691#M51939</guid>
      <dc:creator>David Orwig</dc:creator>
      <dc:date>2010-06-07T14:49:43Z</dc:date>
    </item>
  </channel>
</rss>

