You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用PowerShell脚本无法远程连接数组内部分服务器求助

PowerShell远程部分服务器连接失败排查方案

用户脚本

Enable-PSRemoting -Force
$password = ConvertTo-SecureString "xxxxxxxxx" -AsPlainText -Force 
$username = "NE\a_chermes2" 
$Cred = New-Object System.Management.Automation.PSCredential ($username, $password)

$Computers = @(
    "NESCH11",
    "NESCH12",
    "NESCH13",
    "GLXVWPPSCH00",
    "GLXVWPPSCH01",
    "TWPPNESCH06",
    "TWPPNESCH07",
    "TWPPNESCH08",
    "TWPPNESCH09",
    "TWPPNESCH10",
    "TWPPNEDB01",
    "TWPPNEDB03",
    "GLXVWPPSQL02",
    "TWPPNEWS03.ne.local",
    "TWPPNEWS04.ne.local"
)
#$Computers = $Computers[0]

Write-Host " " 
Invoke-Command -ComputerName $Computers  -Credential $Cred -Scriptblock{Write-Host "I am in server: "  (hostname)}

错误信息

[TWPPNEWS03.ne.local] Connecting to remote server TWPPNEWS03.ne.local failed with the following error message : WinRM cannot complete the operation. Verify that the 
specified computer name is valid, that the computer is accessible over the network, and that a firewall exception for the WinRM service is enabled and allows access 
from this computer. By default, the WinRM firewall exception for public profiles limits access to remote computers within the same local subnet. For more information, 
see the about_Remote_Troubleshooting Help topic.
    + CategoryInfo          : OpenError: (TWPPNEWS03.ne.local:String) [], PSRemotingTransportException
    + FullyQualifiedErrorId : WinRMOperationTimeout,PSSessionStateBroken

排查步骤

1. 验证网络连通性

  • 本地执行 ping TWPPNEWS03.ne.local 和 ping TWPPNEWS04.ne.local,确认网络可达;不通则先排查DNS解析、路由或服务器在线状态
  • 测试WinRM默认端口连通性:Test-NetConnection TWPPNEWS03.ne.local -Port 5985(HTTP)或-Port 5986(HTTPS),确认端口能建立连接

2. 检查目标服务器WinRM配置

  • 远程登录目标服务器,执行 Enable-PSRemoting -Force 确保WinRM服务完成初始化配置
  • 检查WinRM服务状态:Get-Service WinRM,确认服务处于Running状态
  • 查看WinRM监听配置:winrm enumerate winrm/config/listener,确保存在对应IP或*的HTTP/HTTPS监听

3. 防火墙规则校验

  • 目标服务器上执行 Get-NetFirewallRule -Name *WinRM*,确认WinRM相关防火墙规则已启用
  • 若服务器使用公共网络配置文件,默认WinRM仅允许同子网访问,需修改规则扩大IP范围,或切换网络配置文件为私有/域

4. 权限与认证检查

  • 确认NE\a_chermes2账号在目标服务器上属于Administrators组或Remote Management Users组,具备远程管理权限
  • 本地执行 Enter-PSSession -ComputerName TWPPNEWS03.ne.local -Credential $Cred,尝试建立交互式会话,定位是否为认证类问题

5. 名称解析与SPN检查

  • 确认目标服务器DNS解析无歧义,避免出现名称不匹配情况
  • 检查目标服务器SPN记录:setspn -L TWPPNEWS03.ne.local,确保存在WSMAN/TWPPNEWS03.ne.local和WSMAN/TWPPNEWS03的SPN,避免Kerberos认证失败

内容的提问来源于stack exchange,提问作者Hermes1160

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 12:03:33