When you configure WinRM over HTTP with Kerberos,
the firewall and the monitored servers use Kerberos for mutual authentication
and the monitored server encrypts the communication with the firewall
using a negotiated Kerberos session key.
WinRM with
Kerberos supports the aes128-cts-hmac-sha1-96 and aes256-cts-hmac-sha1-96 ciphers.
If the server you want to monitor uses RC4, you must download the
Windows
update and
disable RC4 for Kerberos in the registry
settings of the server you want to monitor.