Remote Tools, Remote Assistance, and Remote Desktop Do Not Function Properly on Computers Running Windows XP SP2
By default, SMS clients that are running Windows XP SP2 cannot be remotely managed by SMS Remote Tools, Remote Assistance, and Remote Desktop because of the default secure Windows Firewall configuration on the client.
WORKAROUND: Update the Windows Firewall settings for computers that run Windows XP SP2 with Group Policy.
Notes:
• Using a procedure below causes all Windows Firewall Group Policy settings in Windows XP SP2 to propagate to the group Policy Objects stored in Active Directory® directory services for the entire domain.
• You can perform a procedure from any computer that is a member of the domain. After you complete a procedure, Group Policy settings are permanent and can be viewed from other Microsoft Management Console (MMC) consoles available on supported operating systems.
To update Group Policy and enable Remote Desktop
1. On a computer that is running Windows XP SP2, open the Group Policy Object Editor, and then navigate to Default Domain Policy, Computer Configuration, Administrative Templates, Network, Network Connections, Windows Firewall, Domain Profile.
2. Select the Windows Firewall: Allow Remote Desktop exception option.
To update Group Policy and enable Remote Assistance
1. On a computer that is running Windows XP SP2, open the Group Policy Object Editor, and then navigate to Default Domain Policy, Computer Configuration, Administrative Templates, Network, Network Connections, Windows Firewall, Domain Profile.
2. Select the Windows Firewall: Define port exceptions option for TCP Port 135 and the Windows Firewall: Define program exceptions option for Helpsvc.exe.
To update Group Policy and enable Remote Tools
•Define port exceptions for the following ports that are necessary for each remote tool.
•TCP port 2701 for general contact, reboot, and ping
•TCP port 2702 for Remote Control
•TCP port 2703 for Chat
•TCP port 2704 for File Transfer