Windows Installation

This page covers installation of all NetXMS components on Windows.

Before proceeding, ensure your system meets the system requirements and that you have prepared the database for the server.

NetXMS components are distributed as separate Windows installers, downloadable from the official NetXMS website:

Installer Component

netxms-server-6.1.0-x64.exe

Server (includes command-line tools and reporting server)

nxagent-6.1.0-x64.exe

Agent (also -x86 and -aarch64 variants)

netxms-client-6.1.0-x64.exe

Desktop management client

netxms-webui-6.1.0-x64.exe

Web management console (bundles Java and Jetty)

Server

Run the Installer

  1. Launch the server installer and follow the setup wizard.

  2. On the Component Selection screen, select:

    • NetXMS Server

    • Command Line Tools (optional)

    • Database client library, if your database is PostgreSQL, MariaDB, or MySQL (for MS SQL Server and Oracle, install the vendor’s client software separately)

    • Reporting Server (optional)

  3. Keep the Initialize database task selected and enter the database connection parameters when prompted.

  4. The installer creates the configuration file at C:\NetXMS\etc\netxmsd.conf and initializes the database schema.

  5. A random password is generated for the admin user and displayed on the final page of the wizard — use the Copy Password button and save it before closing the installer.

  6. The server is registered as a Windows service and started automatically.

Verify Installation

Open the Windows Services console (services.msc) and verify that the NetXMS Core service is running.

Check the log file at C:\NetXMS\log\netxmsd.log for any startup errors.

Post-Installation Steps

After the server is running:

  1. Connect with the management client as admin, using the password shown by the installer (see Initial Credentials)

  2. You will be asked to change the password on first login

  3. Proceed to the Quick Start guide for initial configuration

Firewall Configuration

Ensure the following ports are open on the server host:

Port Protocol Purpose

4701

TCP

Management client connections (desktop client and web management console)

4700

TCP

Agent connections (if agents connect to server)

4703

TCP

Agent tunnel connections

162

UDP

SNMP trap reception

514

UDP

Syslog reception (if enabled)

8000 / 8443

TCP

WebAPI HTTP / HTTPS listeners (only if the WebAPI is enabled and exposed beyond the local host)

Open Windows Defender Firewall with Advanced Security and create inbound rules for each port, or use PowerShell:

New-NetFirewallRule -DisplayName "NetXMS Server" -Direction Inbound -Protocol TCP -LocalPort 4701 -Action Allow
New-NetFirewallRule -DisplayName "NetXMS Agent" -Direction Inbound -Protocol TCP -LocalPort 4700 -Action Allow
New-NetFirewallRule -DisplayName "NetXMS Tunnel" -Direction Inbound -Protocol TCP -LocalPort 4703 -Action Allow
New-NetFirewallRule -DisplayName "SNMP Traps" -Direction Inbound -Protocol UDP -LocalPort 162 -Action Allow

Agent

Installer

Download the NetXMS agent installer (nxagent-6.1.0-x64.exe) and run it on the target machine.

  1. Enter the NetXMS server address when prompted.

  2. The installer creates the configuration file at C:\NetXMS\etc\nxagentd.conf and registers the agent as a Windows service.

  3. The agent starts automatically after installation.

Silent Installation

For mass deployment, use silent installation with command-line parameters. The Windows Agent installer supports configuration, tunnel, subagent, and service options via the command line.

Basic silent install example:

nxagent-{product-version}-x64.exe /VERYSILENT /SUPPRESSMSGBOXES /SERVER=10.0.0.1

For the complete list of installer command-line options, examples, and uninstallation options, see Windows Agent Installer Reference.

Configuration

The configuration file is located at C:\NetXMS\etc\nxagentd.conf and uses the same format as the Linux agent:

MasterServers = 10.0.0.1
LogFile = {syslog}

On Windows, {syslog} directs log output to the Windows Event Log.

Key configuration parameters:

Parameter Default Description

MasterServers

(none)

Comma-separated list of server addresses (IP, hostname, or CIDR) with full control over the agent, including configuration changes and upgrades.

ControlServers

(none)

Servers with intermediate access: read data and execute predefined actions.

Servers

(none)

Servers with read-only access.

SharedSecret

admin

Shared secret for server-agent authentication; must match the secret configured on the server. Used when RequireAuthentication is enabled.

RequireAuthentication

No

Require shared secret authentication for all server connections.

ServerConnection

(none)

Server address for an agent-initiated tunnel connection. See Agent Tunnels.

LogFile

(platform-dependent)

Path to agent log file. Special values: {syslog} (syslog / Windows Event Log), {systemd} (systemd journal), {stdout} (standard output).

DebugLevel

0

Debug verbosity level (0-9); 0 disables debug output.

For the full list of agent configuration parameters, see Agent Configuration.

Agent Tunnels

In environments where agents cannot accept inbound connections (firewalled hosts, NAT, cloud VMs), use agent tunnels. The agent initiates an outbound TLS connection to the server, eliminating the need for inbound port 4700.

Add the following to the agent configuration:

ServerConnection = server.example.com
MasterServers = server.example.com
ServerConnection defines the tunnel endpoint, but MasterServers (or ControlServers/Servers) is also required to authorize the server to communicate with the agent through the tunnel.

The agent connects to the server on port 4703 (TLS) and maintains a persistent tunnel. The server communicates with the agent through this tunnel for all polling and data collection operations.

For detailed tunnel configuration, see Agent Tunnels.

Verifying Agent Connectivity

After installing the agent, verify connectivity from the server using nxget:

nxget 10.0.0.50 System.PlatformName

This should return the agent’s platform information (e.g., windows-x64).

nxget opens a direct connection to the agent on port 4700, so it cannot reach agents that connect through an agent tunnel.

Web Management Console

The NetXMS web management console provides browser-based access to the monitoring system. It is a Java web application deployed on a Jakarta EE-compatible servlet container.

Prerequisites

  • Java Runtime Environment (JRE) 17 or later

  • Apache Tomcat 11 or later, Jetty 12 or later, or any servlet container supporting Jakarta Servlet API 6.0

  • Network access to the NetXMS server on port 4701

Using the Ready-Made Installer

A Windows installer is available that bundles Java, Jetty, and the web console into a single package. Download it from the NetXMS download page:

https://netxms.com/download/releases/6.1/netxms-webui-6.1.0-x64.exe

Run the installer and follow the on-screen prompts. The service starts automatically after installation.

Manual Deployment on Tomcat

Install Java and Tomcat

  1. Download and install a JRE 17 or later from https://adoptium.net/ or the vendor of your choice.

  2. Download Apache Tomcat 11 from https://tomcat.apache.org/ and use the Windows Service installer for production.

Deploy the Web Console WAR

Download the WAR file from the NetXMS download page:

https://netxms.com/download/releases/6.1/nxmc-6.1.0.war

Copy the downloaded file to the Tomcat webapps directory (e.g., C:\Program Files\Apache Software Foundation\Tomcat 11\webapps\nxmc.war).

Tomcat automatically extracts and deploys the application.

Configuration

The web console needs to know the NetXMS server address. The quickest method for a manual Tomcat deployment is to place an nxmc.properties file on the Tomcat classpath (e.g., C:\Program Files\Apache Software Foundation\Tomcat 11\lib\):

server=10.0.0.1

Replace 10.0.0.1 with your NetXMS server address.

Alternatively, set the NXMC_SERVER environment variable in the Windows system environment or in the Tomcat service wrapper configuration.

For the full list of configuration properties, all supported configuration methods (JNDI, properties file, JVM properties, environment variables), and the server address resolution order, see Web Console Configuration Reference.

Restart the Tomcat service (or the ready-made installer service) after making configuration changes.

Access the web console at http://your-server:8080/nxmc (or https://your-server:8443/ for the ready-made installer).

Troubleshooting

Web Console Does Not Start

For Tomcat, check log files at C:\Program Files\Apache Software Foundation\Tomcat 11\logs\catalina.out.

Common issues:

  • Java not found — Ensure JAVA_HOME is set correctly and points to JRE 17 or later

  • Port conflict — Tomcat default port 8080 may be in use by another application

  • Permission denied — Ensure the service account has read access to the WAR file

Cannot Connect to Server

  • Verify the server address via one of the configuration methods above

  • Check that port 4701 is accessible from the web server host

  • Verify the NetXMS server is running

WebAPI

The NetXMS WebAPI provides RESTful HTTP access to the monitoring system, enabling integration with third-party tools, custom dashboards, and automation scripts.

The WebAPI is built into the server: REST endpoints are provided by the webapi server module (webapi.nxm, installed together with the server) and served by the server’s own HTTP listener. No separate service or component is required.

The standalone WebAPI service (nxapisrv) used with older NetXMS versions is deprecated and has been removed.

Enabling the WebAPI

Load the module by adding the following line to C:\NetXMS\etc\netxmsd.conf and restarting the NetXMS Core service:

Module = webapi

By default the API listens for plain HTTP requests on 127.0.0.1:8000. Listener settings are controlled by the [WEBAPI] section of netxmsd.conf:

[WEBAPI]
Port = 8000
# Listen address: loopback (default), any, or a specific IP address
Address = loopback
# Optional HTTPS listener
TLSEnable = yes
TLSPort = 8443
TLSCertificate = C:\NetXMS\etc\webapi.crt
TLSCertificateKey = C:\NetXMS\etc\webapi.key

Configuration Parameters

All parameters belong to the [WEBAPI] section of the server configuration file (netxmsd.conf).

Parameter Description

Enable

Enable or disable the WebAPI listener. Default: yes.

Address

HTTP listen address: loopback, any, or a specific IP address. Default: loopback.

Port

HTTP port. Default: 8000.

TLSEnable

Enable the HTTPS listener. Default: no.

TLSAddress

HTTPS listen address. Default: 0.0.0.0 (all interfaces).

TLSPort

HTTPS port. Default: 8443.

TLSCertificate

Path to the TLS certificate file (PEM format). Required when TLSEnable is yes.

TLSCertificateKey

Path to the TLS private key file (PEM format). Required when TLSEnable is yes.

ReproxyPath

Path to the reproxy binary used for TLS termination. Default: /usr/bin/reproxy (reproxy.exe in the server binary directory on Windows).

The HTTPS listener is provided by a reproxy helper process that the server starts and supervises automatically when TLSEnable is set.

API Usage

See the Linux installation page for authentication and request examples — API usage is identical on all platforms. For the complete API reference, see the REST API section.

Security Considerations

  • The plain HTTP listener binds to the loopback interface by default. To expose the API beyond the local host, enable the TLS listener (TLSEnable) or keep the HTTP listener on loopback behind a reverse proxy.

  • Always use TLS in production. Use certificates from a trusted CA or your internal PKI.

  • Restrict network access to the API port using firewall rules.

Desktop Management Client

The NetXMS desktop management client is distributed as a separate installer, netxms-client-6.1.0-x64.exe, with the following components:

  • NetXMS GUI Client — the desktop management client

  • NetXMS Python Scripting (nxshell) — see NXShell

  • Command Line Tools — nxalarm, nxevent, nxnotify, and nxpush

  • Java Runtime Environment — used by the GUI client and nxshell. Without it, JAVA_HOME must point to a 64-bit Java 17 or later installation.

The desktop client offers the same functionality as the web console and may provide better responsiveness for daily administrative tasks.