Firewall issue can be solved by manually or by using attached scripts.
In the attached zip file (firewall_rules.zip) you will find two batch scripts,
add_ds_firewall_rule.cmd
add_client_firewall_rule.cmd
The first one needs to be applied on the Diagnostic Server machine (elevated permissions), it will enable the following inbound ports:
3843, 40403
And the following outbound ports
80, 443, 40403
For the specific SpotlightDiagnosticServer.exe service executable.
The supported profile is domain (as we only support domain environments)
The second one needs to be applied on every client machine (also elevated permissions), and will enable the following outbound ports for the latest installed Spotlight client executable:
80,443,3843,40403
We’ve tested this on a system with the preferred firewall configuration enabled (i.e. the Microsoft default)