→ 🚀What's New? Join Us for the Fall Product Launch! Register Now !

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
cdphp
Engaged Sweeper
I am trying to figure out the best way to scan isolated environments like labs so I have a more accurate inventory. I have 2 labs with their own domain controllers (isolated sub-domains) What are other people doing? I think I could use lspush in some manner but I have been trying to see if I could poke a hole in the firewall that would let me reach the hosts. It seems like because it is an agentless scan that it would require all kinds of ports to be opened...and security will not be happy with that.
1 ACCEPTED SOLUTION
Hemoco
Lansweeper Alumni
For agentless scanning, you need to either:
- Allow *all* WMI traffic through your firewall(s), as this data is (by default) sent over random ports.
- Set up a fixed WMI port, if you cannot allow all WMI traffic: http://lansweeper.com/kb/20/used-TCP-ports.html

When used with direct server connection, our LsPush scanning agent only requires one open port. You can use the default port, which is 9524, or select your own in the Lansweeper web console under Configuration/Scanning Setup/Server Options. If you select your own port, you will need to restart the Lansweeper service and include your custom port in your LsPush command. More info on LsPush can be found on page 73 and beyond of our online documentation: http://www.lansweeper.com/documentation.pdf

View solution in original post

4 REPLIES 4
cdphp
Engaged Sweeper
Thank you.
cdphp
Engaged Sweeper
Are there any known issues with executing LSPush from a network location rather than deploying it locally? \\server\share\lspush.exe
Hemoco
Lansweeper Alumni
cdphp wrote:
Are there any known issues with executing LSPush from a network location rather than deploying it locally? \\server\share\lspush.exe



No. This even a recommended way in order to have all computers scanned with the latest LsPush version.
Hemoco
Lansweeper Alumni
For agentless scanning, you need to either:
- Allow *all* WMI traffic through your firewall(s), as this data is (by default) sent over random ports.
- Set up a fixed WMI port, if you cannot allow all WMI traffic: http://lansweeper.com/kb/20/used-TCP-ports.html

When used with direct server connection, our LsPush scanning agent only requires one open port. You can use the default port, which is 9524, or select your own in the Lansweeper web console under Configuration/Scanning Setup/Server Options. If you select your own port, you will need to restart the Lansweeper service and include your custom port in your LsPush command. More info on LsPush can be found on page 73 and beyond of our online documentation: http://www.lansweeper.com/documentation.pdf