<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WinRM-HTTP Connection Refused in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/512515#M106494</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;You'll need a policy rule from the management IP to the domain servers, remember that it does not use the default port, so you must define "any" in "service/url category".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EnricRipoll_0-1661165148934.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43256i75DB13FF83C79ECA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="EnricRipoll_0-1661165148934.png" alt="EnricRipoll_0-1661165148934.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;bye,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 22 Aug 2022 10:53:35 GMT</pubDate>
    <dc:creator>EnricRipoll</dc:creator>
    <dc:date>2022-08-22T10:53:35Z</dc:date>
    <item>
      <title>WinRM-HTTP Connection Refused</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/444954#M100414</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using agentless user-id with a Windows Server 2012 AD through WMI, we recently updated the server, and it started throwing &lt;EM&gt;Authentication Error 10036&lt;/EM&gt; flooding our Windows logs. We've searched and troubleshooted the problem for a long time and nothing worked, the only workaround that we think might work is to change the authentication protocol from WMI to WinRM-HTTP. (We cannot roll back the update for vulnerability requirements)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We used this guide&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/user-id/map-ip-addresses-to-users/configure-server-monitoring-using-winrm.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/user-id/map-ip-addresses-to-users/configure-server-monitoring-using-winrm.html&lt;/A&gt;&amp;nbsp;to set up the configuration, and once we committed we're getting "Connection Refused(0)". The user-id logs are not specifying the error, just a "connection failed, error=0"&lt;/P&gt;&lt;P&gt;Likewise, we also troubleshooted everything, from the configs to the service account having the correct permissions as per Palo Alto's recommendation, and still.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 09:14:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/444954#M100414</guid>
      <dc:creator>echahine</dc:creator>
      <dc:date>2021-11-02T09:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: WinRM-HTTP Connection Refused</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/445041#M100420</link>
      <description>&lt;P&gt;I also changed from wmi to winrm and seems ok... &amp;nbsp; have you tested your kerberos profile?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 18:39:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/445041#M100420</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-11-02T18:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: WinRM-HTTP Connection Refused</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/445150#M100438</link>
      <description>&lt;P&gt;Yes, and it was successful.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 09:00:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/445150#M100438</guid>
      <dc:creator>echahine</dc:creator>
      <dc:date>2021-11-03T09:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: WinRM-HTTP Connection Refused</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/458227#M101887</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;happy new year ! &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have exactly the same issue...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Everything is configured by following Palo's instructions, but always "Connection refused (0)"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any ideas?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/183298"&gt;@echahine&lt;/a&gt;&amp;nbsp;have you solved on your side ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank's&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 10:46:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/458227#M101887</guid>
      <dc:creator>M.Geinoz</dc:creator>
      <dc:date>2022-01-12T10:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: WinRM-HTTP Connection Refused</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/458249#M101891</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We weren't able to solve the issue using WinRM HTTP, we did however migrate from PAN-OS Integrated User-ID agent to Windows User-ID Agent which solved the&amp;nbsp;&lt;EM&gt;Authentication Error 10036&amp;nbsp;&lt;/EM&gt;isuue.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 11:30:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/458249#M101891</guid>
      <dc:creator>echahine</dc:creator>
      <dc:date>2022-01-12T11:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: WinRM-HTTP Connection Refused</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/458406#M101898</link>
      <description>&lt;PRE&gt;&lt;SPAN class=""&gt;Hi,
Thank you very much for the information, now it works with &lt;SPAN&gt;Windows User-ID Agent !&lt;BR /&gt;Why do Palo make PAN-OS Integrated User-ID agent available if it doesn't work ...&lt;BR /&gt;Have a nice day&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 12 Jan 2022 15:39:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/458406#M101898</guid>
      <dc:creator>M.Geinoz</dc:creator>
      <dc:date>2022-01-12T15:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: WinRM-HTTP Connection Refused</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/458412#M101899</link>
      <description>&lt;P&gt;It's actually a Windows hardening issue. But you're right Palo Alto should be compatible with these hardenings already since it's an old recurring issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Glad to help!&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 16:03:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/458412#M101899</guid>
      <dc:creator>echahine</dc:creator>
      <dc:date>2022-01-12T16:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: WinRM-HTTP Connection Refused</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/512515#M106494</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;You'll need a policy rule from the management IP to the domain servers, remember that it does not use the default port, so you must define "any" in "service/url category".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EnricRipoll_0-1661165148934.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43256i75DB13FF83C79ECA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="EnricRipoll_0-1661165148934.png" alt="EnricRipoll_0-1661165148934.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;bye,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 10:53:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/512515#M106494</guid>
      <dc:creator>EnricRipoll</dc:creator>
      <dc:date>2022-08-22T10:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: WinRM-HTTP Connection Refused</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/554557#M112687</link>
      <description>&lt;P&gt;Several of you have already gone through the&amp;nbsp; winRM fixes&amp;nbsp; under&amp;nbsp;HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WinRM\Client &amp;amp;&amp;nbsp;HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WinRM\Server&amp;nbsp;fixes,&amp;nbsp; the below settings in windows worked for me ( Panos 10.1.0 with win2k12 R2)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://serverfault.com/questions/841689/changing-winrm-settings-from-script" target="_blank"&gt;https://serverfault.com/questions/841689/changing-winrm-settings-from-script&lt;/A&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Edit Group Policy.&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Administrative Templates -&amp;gt; Windows Component -&amp;gt; Winodws Remote Management(WinRM) -&amp;gt; WinRM Client -&amp;gt; make all as not configured&amp;nbsp;&lt;A href="https://i.stack.imgur.com/MSCol.png" rel="nofollow noreferrer" target="_blank"&gt;enter image description here&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Administrative Templates -&amp;gt; Windows Component -&amp;gt; Winodws Remote Management(WinRM) -&amp;gt; WinRM Service-&amp;gt; make Allow Basic authentication as not configured&amp;nbsp;&lt;A href="https://i.stack.imgur.com/XgdFa.png" rel="nofollow noreferrer" target="_blank"&gt;enter image description here&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;-Open powershell and run #&amp;nbsp;gpupdate /force&lt;/P&gt;
&lt;P&gt;Attaching my environment settings screenshots.&lt;/P&gt;
&lt;P&gt;This will work the magic!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 20:28:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/winrm-http-connection-refused/m-p/554557#M112687</guid>
      <dc:creator>stambe</dc:creator>
      <dc:date>2023-08-21T20:28:47Z</dc:date>
    </item>
  </channel>
</rss>

