# ECE On premise 7.12 Fleet failure to Enroll, windows 10 system

**URL:** <https://discuss.elastic.co/t/ece-on-premise-7-12-fleet-failure-to-enroll-windows-10-system/268929>\
**Category:** Elasticsearch\
**Created:** [March 31, 2021, 3:39pm UTC](https://discuss.elastic.co/t/ece-on-premise-7-12-fleet-failure-to-enroll-windows-10-system/268929 "2021-03-31T15:39:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nicholas\_Rowe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicholas_rowe/32/85199_2.png) [@Nicholas\_Rowe](https://discuss.elastic.co/u/Nicholas_Rowe)\
**Post date:** [March 31, 2021, 3:39pm UTC](https://discuss.elastic.co/t/ece-on-premise-7-12-fleet-failure-to-enroll-windows-10-system/268929/1 "2021-03-31T15:39:44Z")

</div>

I just setup an ECE instance using 7.9 (which I believe is the latest) and spun up a cluster for security using version 7.12. I setup a new agent and tried to enroll a windows 10 target workstation as outlined, but an getting the following error.

```auto
Error while enrolling: fail to execute the HTTP POST request: Post https://235b02623be74f1999ce940d4fd05ce1.192.168.1.121.ip.es.io:443: dial tcp 192.168.1.121:443: connectex: No connection could be made because the target machine actively refused it.

```

Below is the command I used to try and install it, but I get the same error every time. I also tried using the -i flag for insecure, but no change. It simply does not want to enroll.

.\elastic-agent.exe install -f --kibana-url=[https://235b02623be74f1999ce940d4fd05ce1.192.168.1.121.ip.es.io:443](https://235b02623be74f1999ce940d4fd05ce1.192.168.1.121.ip.es.io/) --enrollment-token=QTZjU2huZ0ItX2JTWHRwYzU3S3I6NkloTVd1ZDRUU2EteEtpRmEtLXc2dw==

Based on the error message it looks like kibana/fleet is refusing the connection. I verified the windows firewall on the endpoint is turned off. No network firewall in between the endpoint and the elastic cluster.

Why would Kibana actively refuse the agent enrollment?

---

<div class="post-metadata">

**Author:** ![Nicholas\_Rowe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicholas_rowe/32/85199_2.png) [@Nicholas\_Rowe](https://discuss.elastic.co/u/Nicholas_Rowe)\
**Post date:** [April 6, 2021, 3:00am UTC](https://discuss.elastic.co/t/ece-on-premise-7-12-fleet-failure-to-enroll-windows-10-system/268929/2 "2021-04-06T03:00:09Z")

</div>

Figured it out, looks like when you install ECE on premise or in a private datacenter, the default target URLS for the fleet agents are set to 443, but kibana and ES don't listen on those ports. They listen on 9243, so I changed the default URL endpoints for the fleet agents to use 9243, and it worked like a charm next time I tried to enroll.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 4, 2021, 3:00am UTC](https://discuss.elastic.co/t/ece-on-premise-7-12-fleet-failure-to-enroll-windows-10-system/268929/3 "2021-05-04T03:00:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
