{"id":7709,"date":"2014-01-05T12:15:13","date_gmt":"2014-01-05T04:15:13","guid":{"rendered":"http:\/\/blog.pmail.idv.tw\/?p=7709"},"modified":"2014-01-05T12:15:13","modified_gmt":"2014-01-05T04:15:13","slug":"hyper-v-vmm-%e6%9c%8d%e5%8b%99%e5%a4%b1%e6%95%97%ef%bc%8c%e4%b8%94%e4%ba%8b%e4%bb%b6%e8%ad%98%e5%88%a5%e7%a2%bc-14050-dynamicportrange-%e5%b7%b2%e5%9c%a8-windows-server-2012","status":"publish","type":"post","link":"https:\/\/blog.pmail.idv.tw\/?p=7709","title":{"rendered":"Hyper-V VMM \u670d\u52d9\u5931\u6557\uff0c\u4e14\u4e8b\u4ef6\u8b58\u5225\u78bc 14050 dynamicportrange \u5df2\u5728 Windows Server 2012"},"content":{"rendered":"<p>\u5982\u679c\u6709\u4f7f\u7528 VMM 2012 sp1 \u7ba1\u7406Windows Server 2012 Hyper-V\u7684\u670b\u53cb\uff0c\u82e5\u6709\u767c\u751f\u5931\u6557<\/p>\n<p>\u4e8b\u4ef6\u65e5\u8a8c\u6709\u51fa\u73fe\u985e\u4f3c\u5982\u4e0b\u8a0a\u606f<\/p>\n<pre>Log Name: Microsoft-Windows-Hyper-V-VMMS-Admin\nSource: Microsoft-Windows-Hyper-V-VMMS\nDate: &lt;Date&gt; &lt;Time&gt;\nEvent ID: 14050\nLevel: Error\nDescription: Failed to register service principal name.\nEvent Xml: \u2026\n&lt;Parameter0&gt;Hyper-V Replica Service&lt;\/Parameter0&gt;<\/pre>\n<p>&nbsp;<\/p>\n<p><!--more--><\/p>\n<p>\u5fae\u8edf\u5df2\u7d93\u57282014.1.2\u63d0\u4f9b\u7d55\u6c7a\u65b9\u6848:kb2761899<\/p>\n<p><a href=\"http:\/\/support.microsoft.com\/kb\/2761899\">http:\/\/support.microsoft.com\/kb\/2761899<\/a><\/p>\n<p>\u539f\u56e0<\/p>\n<p>\u5982\u679c TCP \u52d5\u614b\u9023\u63a5\u57e0\u7bc4\u570d\u8d85\u51fa\u9810\u8a2d\u7bc4\u570d\uff0c\u53ef\u80fd\u6703\u767c\u751f\u9019\u500b\u554f\u984c\u3002Hyper-V \u865b\u64ec\u7ba1\u7406\u670d\u52d9 (Vmms.exe) \u53ef\u8b93\u60a8\u4f7f\u7528 Windows \u670d\u52d9\u5f37\u5316\uff0c\u4e26\u9650\u5236\u672c\u8eab\u52d5\u614b\u9023\u63a5\u57e0\u7bc4\u570d\u3002<br \/>\u5982\u679c\u8981\u5224\u65b7 TCP \u52d5\u614b\u9023\u63a5\u57e0\u7bc4\u570d\uff0c\u8acb\u5728\u63d0\u9ad8\u6b0a\u9650\u7684\u547d\u4ee4\u63d0\u793a\u5b57\u5143\u57f7\u884c\u4e0b\u5217\u547d\u4ee4\uff1a<\/p>\n<pre>C:\\&gt;netsh int ipv4 show dynamicportrange tcp\nProtocol tcp Dynamic Port Range\n---------------------------------\nStart Port      : 49152\nNumber of Ports : 16384<\/pre>\n<p>\u82e5\u8981\u89e3\u6c7a\u9019\u500b\u554f\u984c\uff0c\u8acb\u57f7\u884c\u4e0b\u5217\u6307\u4ee4\u78bc\u4e00\u6b21\uff0c\u6bcf\u500b\u53d7\u5f71\u97ff Hyper-V \u4e3b\u6a5f\u3002\u6b64\u6307\u4ee4\u78bc\u52a0\u5165\u81ea\u8a02\u7684\u901a\u8a0a\u57e0\u7bc4\u570d\uff0c\u624d\u80fd\u555f\u7528\u901a\u8a0a 9000 \u5230 9999 \u4e4b\u9593\u7684\u984d\u5916\u7684\u9023\u63a5\u57e0\u7bc4\u570d\u7684 Vmms.exe\u3002\u6307\u4ee4\u78bc\u53ef\u4ee5\u8996\u9700\u8981\u4fee\u6539\u3002<br \/>\u82e5\u8981\u8a2d\u5b9a\u6307\u4ee4\u78bc\uff0c\u4ee5\u65b0\u589e\u81ea\u8a02\u7684\u9023\u63a5\u57e0\u7bc4\u570d\uff0c\u8acb\u4f9d\u7167\u4e0b\u5217\u6b65\u9a5f\u57f7\u884c\uff1a<\/p>\n<ol>\n<li>\u555f\u52d5\u6587\u5b57\u7de8\u8f2f\u5668\uff0c\u4f8b\u5982 \u300c \u8a18\u4e8b\u672c \u300d\u3002\n<li>\u8907\u88fd\u4e0b\u5217\u7a0b\u5f0f\u78bc\u4e2d\uff0c\u4e26\u5c07\u7a0b\u5f0f\u78bc\u518d\u8cbc\u5230\u6587\u5b57\u6a94\u6848\uff1a\n<p><code><\/p>\n<pre>'This VBScript adds a port range from 9000 to 9999 for outgoing traffic  \n'run as cscript addportrange.vbs on the hyper-v host\n\noption explicit\n\n'IP protocols\nconst NET_FW_IP_PROTOCOL_TCP = 6\nconst NET_FW_IP_PROTOCOL_UDP = 17\n\n'Action\nconst NET_FW_ACTION_BLOCK = 0\nconst NET_FW_ACTION_ALLOW = 1\n\n'Direction\nconst NET_FW_RULE_DIR_IN = 1\nconst NET_FW_RULE_DIR_OUT = 2\n\n'Create the FwPolicy2 object.\nDim fwPolicy2\nSet fwPolicy2 = CreateObject(\"HNetCfg.FwPolicy2\")\n\n'Get the Service Restriction object for the local firewall policy.\nDim ServiceRestriction\nSet ServiceRestriction = fwPolicy2.ServiceRestriction\n\n'If the service requires sending\/receiving certain type of traffic, then add \"allow\" WSH rules as follows\n'Get the collection of Windows Service Hardening networking rules\n\nDim wshRules\nSet wshRules = ServiceRestriction.Rules\n\n'Add outbound WSH allow rules\nDim NewOutboundRule\nSet NewOutboundRule = CreateObject(\"HNetCfg.FWRule\")\nNewOutboundRule.Name = \"Allow outbound traffic from service to TCP 9000 to 9999\"\nNewOutboundRule.ApplicationName = \"%systemDrive%\\WINDOWS\\system32\\vmms.exe\"\nNewOutboundRule.ServiceName = \"vmms\"\nNewOutboundRule.Protocol = NET_FW_IP_PROTOCOL_TCP\nNewOutboundRule.RemotePorts = \"9000-9999\"\nNewOutboundRule.Action = NET_FW_ACTION_ALLOW\nNewOutboundRule.Direction = NET_FW_RULE_DIR_OUT\nNewOutboundRule.Enabled = true\nwshRules.Add NewOutboundRule\n\n'end of script<\/pre>\n<p><\/code><\/p>\n<li>\u5c07\u6a94\u6848\u5132\u5b58\u70ba&#8221;Addportrange.vbs&#8221;(\u5305\u542b\u5f15\u865f)\u3002\u6b63\u78ba\uff0c\u9019\u6703\u5efa\u7acb\u70ba\u5177\u6709.vbs \u526f\u6a94\u540d\u7684\u6a94\u6848\u3002\u6a94\u6848\u5716\u793a\u6703\u5f9e [\u8a18\u4e8b\u672c] \u5716\u793a\u8b8a\u66f4\u70ba\u6307\u4ee4\u78bc\u5716\u793a\u3002\n<li>\u57f7\u884c cscript \u6307\u4ee4\u78bc\u3002<\/li>\n<\/ol>\n<div class=\"21cd169d3c0f71e95b84db320302cb4a\" data-index=\"1\" style=\"float: right; margin:10px 0 10px 10px;\">\n<script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-8711325745898650\"\r\n     crossorigin=\"anonymous\"><\/script>\n<\/div>\n\n<div style=\"font-size: 0px; height: 0px; line-height: 0px; margin: 0; padding: 0; clear: both;\"><\/div>","protected":false},"excerpt":{"rendered":"<p>\u5982\u679c\u6709\u4f7f\u7528 VMM 2012 sp1 \u7ba1\u7406Windows Server 2012 &hellip; <a href=\"https:\/\/blog.pmail.idv.tw\/?p=7709\">\u95b1\u8b80\u5168\u6587 <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[57,12],"tags":[],"class_list":["post-7709","post","type-post","status-publish","format-standard","hentry","category-hyper-v","category-vm"],"_links":{"self":[{"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=\/wp\/v2\/posts\/7709","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=7709"}],"version-history":[{"count":0,"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=\/wp\/v2\/posts\/7709\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=7709"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=7709"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.pmail.idv.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=7709"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}