Introduction
Before running any automation against Windows hosts, you need to verify that Ansible can connect and execute commands. The win_ping module is the standard connectivity test for Windows managed nodes — it verifies WinRM access and that PowerShell is available to execute Ansible modules.
This is the Windows equivalent of the Linux ping module.
What Does win_ping Actually Test?
Unlike network ICMP ping, win_ping tests the entire Ansible communication chain:
- WinRM connectivity — Can Ansible reach the Windows host over WinRM (HTTP/HTTPS)?
- Authentication — Are the credentials valid?
- PowerShell execution — Is PowerShell available and functional?
- Module execution — Can Ansible transfer and execute a module on the remote host?
If win_ping succeeds, your Windows host is fully ready for Ansible automation.
Module Reference
Full name: ansible.windows.win_ping
Collection: ansible.windows
Parameters
| Parameter | Type | Default | Description |
|---|---|---|---|
data | string | pong | Text to return in the response |
Return Values
| Key | Type | Description |
|---|---|---|
ping | string | The value of the data parameter (default: pong) |
Basic Playbook
---
- name: Test Windows host connectivity
hosts: windows
gather_facts: false
tasks:
- name: Test WinRM connection
ansible.windows.win_ping:
Run it:
ansible-playbook win_ping.yml -i inventory.ini
Expected output:
TASK [Test WinRM connection] ***************
ok: [win-server01] => {
"changed": false,
"ping": "pong"
}
Ad-Hoc Command
For a quick test without a playbook:
ansible windows -m ansible.windows.win_ping -i inventory.ini
Or test a single host:
ansible win-server01 -m ansible.windows.win_ping -i inventory.ini
Inventory Configuration for Windows
Windows hosts require WinRM-specific variables in your inventory:
[windows]
win-server01 ansible_host=192.168.1.100
win-server02 ansible_host=192.168.1.101
[windows:vars]
ansible_user=Administrator
ansible_password=SecureP@ss123
ansible_connection=winrm
ansible_winrm_transport=ntlm
ansible_winrm_server_cert_validation=ignore
ansible_port=5986
Connection Variables Explained
| Variable | Description | Common Values |
|---|---|---|
ansible_connection | Connection plugin | winrm (required for Windows) |
ansible_winrm_transport | Authentication method | ntlm, kerberos, basic, credssp |
ansible_port | WinRM port | 5985 (HTTP), 5986 (HTTPS) |
ansible_winrm_server_cert_validation | SSL certificate validation | validate, ignore |
ansible_winrm_scheme | HTTP or HTTPS | http, https |
Setting Up WinRM on Windows
Before win_ping can work, WinRM must be configured on the Windows host.
Quick Setup (PowerShell as Administrator)
# Enable WinRM
winrm quickconfig -force
# Allow basic authentication (for testing)
Set-Item -Path WSMan:\localhost\Service\Auth\Basic -Value $true
# Allow unencrypted traffic (for testing only)
Set-Item -Path WSMan:\localhost\Service\AllowUnencrypted -Value $true
# Configure HTTPS listener (production)
$cert = New-SelfSignedCertificate -DnsName $(hostname) -CertStoreLocation Cert:\LocalMachine\My
winrm create winrm/config/Listener?Address=*+Transport=HTTPS "@{Hostname=`"$(hostname)`"; CertificateThumbprint=`"$($cert.Thumbprint)`"}"
Using the ConfigureRemotingForAnsible.ps1 Script
Ansible provides a convenience script:
# Download and run
$url = "https://raw.githubusercontent.com/ansible/ansible-documentation/devel/examples/scripts/ConfigureRemotingForAnsible.ps1"
$file = "$env:temp\ConfigureRemotingForAnsible.ps1"
(New-Object -TypeName System.Net.WebClient).DownloadFile($url, $file)
powershell.exe -ExecutionPolicy ByPass -File $file
Verify WinRM Configuration
# Check WinRM service
Get-Service WinRM
# List listeners
winrm enumerate winrm/config/Listener
# Test locally
winrm identify -r:http://localhost:5985 -auth:basic -u:Administrator -p:Password
Custom Data Parameter
Test with custom response data:
- name: Test with custom data
ansible.windows.win_ping:
data: "alive"
register: result
- name: Show result
ansible.builtin.debug:
msg: "Host responded: {{ result.ping }}"
Using win_ping in Health Checks
Check Multiple Hosts with Error Handling
- name: Windows health check
hosts: windows
gather_facts: false
tasks:
- name: Test connectivity
ansible.windows.win_ping:
register: ping_result
ignore_unreachable: true
- name: Report unreachable hosts
ansible.builtin.debug:
msg: "WARNING: {{ inventory_hostname }} is unreachable!"
when: ping_result.unreachable is defined and ping_result.unreachable
- name: Continue with reachable hosts only
ansible.builtin.debug:
msg: "{{ inventory_hostname }} is ready for automation"
when: ping_result.ping is defined
Pre-Flight Check Before Deployment
- name: Pre-deployment connectivity check
hosts: windows_servers
gather_facts: false
tasks:
- name: Verify all hosts are reachable
ansible.windows.win_ping:
register: connectivity
- name: Fail fast if any host is down
ansible.builtin.fail:
msg: "Cannot proceed — {{ inventory_hostname }} is unreachable"
when: connectivity is failed
Troubleshooting win_ping Failures
"winrm or requests is not installed"
fatal: [host]: FAILED! => {"msg": "winrm or requests is not installed"}
Fix: Install the pywinrm library on the Ansible control node:
pip install pywinrm
"Connection refused" or Timeout
fatal: [host]: UNREACHABLE! => {"msg": "plaintext: HTTPConnectionPool... Connection refused"}
Causes and fixes:
- WinRM service not running →
Start-Service WinRMon Windows host - Firewall blocking port 5985/5986 → Open the port in Windows Firewall
- Wrong port in inventory → Verify
ansible_portmatches WinRM listener
"401 Unauthorized"
fatal: [host]: UNREACHABLE! => {"msg": "the specified credentials were rejected by the server"}
Fixes:
- Verify username/password
- Check
ansible_winrm_transportmatches server configuration - For domain accounts, use
user@DOMAIN.COMformat - Enable the required auth method on WinRM
"SSL: CERTIFICATE_VERIFY_FAILED"
fatal: [host]: UNREACHABLE! => {"msg": "ssl: certificate verify failed"}
Fix: Either install a valid certificate or set:
ansible_winrm_server_cert_validation=ignore
win_ping vs ping
| Feature | win_ping | ping |
|---|---|---|
| Target OS | Windows | Linux/macOS/Unix |
| Connection | WinRM | SSH |
| Shell | PowerShell | sh/bash |
| Collection | ansible.windows | ansible.builtin |
| Parameters | data | data |
Related Articles
- Test Linux Host Availability: Ansible ping Module
- Ansible win_copy — Copy Files to Windows Hosts
- Ansible win_reboot — Reboot Windows Servers
- Automating Windows with Ansible and WinRM
- Check Directory Exists on Windows: win_stat
- Ansible Connection Failed Errors
- How to Install Ansible
Conclusion
The win_ping module is the essential first step for any Windows automation with Ansible. It validates the complete communication chain — WinRM connectivity, authentication, and PowerShell execution — in a single test. If win_ping returns pong, your Windows host is ready for automation. If it fails, the error messages guide you directly to the issue: missing pywinrm, WinRM not configured, firewall blocking, or authentication problems.