<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WMI query through ASA Firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/wmi-query-through-asa-firewall/m-p/1933154#M457577</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was looking at fixing the ports for WMI but I needed it to come from an independent source.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There’s a whole pile of politics involved but if it comes for an independent source it gives it more credence. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As much as I would like to use Solar Winds the support company is a software development house believes that if it needs software the they can write it better than anyone else…&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Richard Daldy (MF IT)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 02 Apr 2012 11:03:51 GMT</pubDate>
    <dc:creator>richard.daldy</dc:creator>
    <dc:date>2012-04-02T11:03:51Z</dc:date>
    <item>
      <title>WMI query through ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/wmi-query-through-asa-firewall/m-p/1933152#M457575</link>
      <description>&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;I'm a newbie - please be patient&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;We have an ASA firewall that has several DMZ VLANs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;A support company that responsible for the SQL Servers wants to use WMI to query server health. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;Their monitoring server currently on the internal lan, eight SQL servers on the internal lan and six of the SQL Servers are in the DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Two of the SQL Servers in the DMZ are 2003x32 Standard Edition and four are 2008R2x64 Enterprise Edition&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;The question is the ports that need to be open for Windows 2003 is concerningly large tcp/1025-65535, tcp/135&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;What are everyone’s thoughts on opening up such a large range?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;Is there a better way of doing this – unfortunately getting the monitoring software rewritten is not an option and nor is going Linux&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;PS - if this has already been asked can someone point me to the discussions&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:48:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wmi-query-through-asa-firewall/m-p/1933152#M457575</guid>
      <dc:creator>richard.daldy</dc:creator>
      <dc:date>2019-03-11T22:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: WMI query through ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/wmi-query-through-asa-firewall/m-p/1933153#M457576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I would say that that is a No No&lt;/P&gt;&lt;P&gt;But that depends on the environment, for some (most) i woulds say its not ok, but some might feel that they do not need that much security.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WMI is a bit tough on firewalls.&lt;/P&gt;&lt;P&gt;But there are ways to limit the ports used by WMI&lt;/P&gt;&lt;P&gt;fx you can set it to use Fixed ports. and so on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sure it makes the server guys a little less happy since it does not work from the start and they have to make some changes but the added security is well worth the fight.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a link to solarwinds for people with the same problem.and an answer that seems to work &lt;/P&gt;&lt;P&gt;(i have not tested this) from ASH J Kent. (almost at the bottom)&lt;/P&gt;&lt;P&gt;&lt;A href="http://thwack.solarwinds.com/forums/68/application--server-management/21/server--application-monitor/16415/wmi-monitoring-through-firewal/" rel="nofollow"&gt;http://thwack.solarwinds.com/forums/68/application--server-management/21/server--application-monitor/16415/wmi-monitoring-through-firewal/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is one from MSDN&lt;/P&gt;&lt;P&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/windows/desktop/bb219447(v=vs.85).aspx"&gt;http://msdn.microsoft.com/en-us/library/windows/desktop/bb219447(v=vs.85).aspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2012 08:22:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wmi-query-through-asa-firewall/m-p/1933153#M457576</guid>
      <dc:creator>hobbe</dc:creator>
      <dc:date>2012-03-30T08:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: WMI query through ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/wmi-query-through-asa-firewall/m-p/1933154#M457577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was looking at fixing the ports for WMI but I needed it to come from an independent source.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There’s a whole pile of politics involved but if it comes for an independent source it gives it more credence. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As much as I would like to use Solar Winds the support company is a software development house believes that if it needs software the they can write it better than anyone else…&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Richard Daldy (MF IT)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Apr 2012 11:03:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wmi-query-through-asa-firewall/m-p/1933154#M457577</guid>
      <dc:creator>richard.daldy</dc:creator>
      <dc:date>2012-04-02T11:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: WMI query through ASA Firewall</title>
      <link>https://community.cisco.com/t5/network-security/wmi-query-through-asa-firewall/m-p/3334504#M457578</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have the same issue as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this case, can we use the inspect engine on firewall to resolve this issue instead of limit the ports on the windows server?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 18:22:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/wmi-query-through-asa-firewall/m-p/3334504#M457578</guid>
      <dc:creator>Ge Qu</dc:creator>
      <dc:date>2018-02-20T18:22:05Z</dc:date>
    </item>
  </channel>
</rss>

