Forums on Intune, SCCM, and Windows 11

Welcome to the forums. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your topics and posts, as well as connect with other members through your own private inbox!

NEW Configuration Manager 2111 | Ephemeral Ports Maxed Out

  • Thread starter Thread starter Pixar
  • Start date Start date
  • Replies Replies 0
  • Views Views 1K

Pixar

New Member
Messages
4
Solutions
1
Reaction score
0
Points
1
We updated our MECM environment to 2111 last year. There seems to be some kind of change to the client that I'm unable to locate. This issue has started to pop up now, because it takes time for the maximum number of ephemeral ports to be reached. After a period of time, our managed clients are running into the maximum number of ephemeral ports which is preventing the clients from communicating with MECM, AD, etc. The machines require a restart to purge the open sessions (or what is described in the next paragraph).

The processes that are keeping the ports open are WMIPrvSE.exe and svchost.exe. Restarting the IPSec Policy Agent service clears the ports; however, the clients still cannot connect establish new connections. You must also restart the Windows Management Instrumentation service. The MECM Client is doing some type of WMI queries and keeping the sessions open. The IPSec Policy Agent service did not start automatically on our client machines until we upgraded to v.2111.

Running netstat shows multiple connections on the system to itself (see image).

To verify if it's MECM causing the issue, a test machine experiencing the symptoms had the client removed. It's been up for a few days and total number of ephemeral ports open has not increased.

Any thoughts on what could be causing this would be greatly appreciated!
 

Attachments

  • netstat.png
    netstat.png
    426.9 KB · Views: 3
Last edited:
Back
Top