Thank you very much for your reply. Nowadays it happans really seldom
somebody is answering in the MS newsgroups the questions.
Mike T. wrote:
> Replies embedded:
>
> "kakii" <user RemoveThis @domain.invalid> schrieb im Newsbeitrag
> news:%23qzbFzgyGHA.1292@TK2MSFTNGP03.phx.gbl...
>> There are some MS instructions regarding firewall configuration
>> for the purpose of running win xp remote assistance.
>> MS states only the port 3389 shall be opened.
>> But more details on that filter rule are missing.
>>
>
> Are you referring to Windows Firewall, another software firewall, or a
> hardware firewall (e.g. in your router)?
on both PC's runs the Kerio Personal Firewall - software, no routers
present on both sites, not proxy servers or similar, no LANs, etc.
Both PC's connected to internet only through ADSL-Modem, these are using
windows xp dial-up connections, and the Kerio PFW firewalls.
>
>> 1. Does it apply to the novice's or the expert's PC ?
> It applies to the novice's PC. You'll also need to make sure that Windows is
> set up to allow it on the novice's machine. You'll need to right-click the
> "My Computer" icon, select "Properties". On the "Remote" tab, make sure the
> box "Allow Remote Assistance invitations to be sent from this computer" is
> checked.
yes, I'm aware of this option. Checked all the time.
>
>> 2. Is that for inbound or the outbound traffic ?
> I'm not 100% sure, but I believe inbound.
Does the expert PC requires 3389 to be open for outbound/inbound traffic
too ?
>
>> 3. What protocol is this for, TCP or UDP ?
> TCP.
>
>> 4. What application has to be associated with this packet filter rule ?
> If you're referring to Windows Firewall, the program would be "Remote
> Assistance". It's already on the list of programs in the Exceptions list, so
> all you'd need to do is check the box and you're done, unless you want to
> change the scope of the exception (for example, only allowing certain IP
> addresses or within your own subnet). Keep in mind you'll need to log on
> with an account that has Administrator rights to do this. On a standard XP
> installation, the path to the executable is C:\Windows\system32\sessmgr.exe.
>
>> I'g going to run win xp remote assistance in following configuration:
>> - expert's PC: win xp pro sp2
>> - novice's PC: win xp pro sp2
>> - both PC's connected to internet via DSL modem
>> - on both PC's personal firewall running, no router hardware
> Here's the important question: When you say "personal firewall", are you
> referring to theWindows Firewall built into XP, or are you referring to a
> third-party product?
see above please
>
>> - both PC's operate in single, no LANs present
>>
>> How exact should the firewall filter rules to be set for both PC's
>> if the novice's generates invitation from Win Help and Support application
>> and sends it to expert in a file ?
>>
>> How exact should the firewall filter rules to be set for both PC's
>> if the novice's generates invitation from Win Help and Support application
>> and then his choice is the win messenger to send the invitation ?
>>
>> How exact should the firewall filter rules to be set for both PC's
>> if the novice's does not use Windows Help and Support application at
>> all but starts the windows messenger to invite expert to assistance ?
>>
>
> Any of these scenarios should work automatically with the configuration
> stated above.
>
>
> Mike
>
> >> Stay informed about: configuring firewall for remote assistance