Welcome to the { mindfrost82.com } forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

Go Back   { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Microsoft > Windows Server

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 04-05-2008, 07:13 PM
Usenet
 
Posts: n/a
XP Firewall GPO not applying at startup

I have the following GPO applied to an OU containing our workstations:

Computer Configuration (Enabled)hide
Policieshide
Windows Settingshide
Security Settingshide
Windows Firewall with Advanced Securityhide
Global Settingshide
Policy Setting
Policy version Not Configured
Disable stateful FTP Not Configured
Disable stateful PPTP Not Configured
IPsec exempt Not Configured
IPsec through NAT Not Configured
Preshared key encoding Not Configured
SA idle time Not Configured
Strong CRL check Not Configured

Domain Profile Settingshide
Policy Setting
Firewall state Off
Inbound connections Not Configured
Outbound connections Not Configured
Apply local firewall rules Not Configured
Apply local connection security rules Not Configured
Display notifications Not Configured
Allow unicast responses Not Configured
Log dropped packets Not Configured
Log successful connections Not Configured
Log file path Not Configured
Log file maximum size (KB) Not Configured

Connection Security Settingshide
Administrative Templateshide
Policy definitions (ADMX files) retrieved from the local
machine.Network/Network Connections/Windows Firewall/Domain Profilehide
Policy Setting Comment
Windows Firewall: Protect all network connections Disabled

Network/Network Connections/Windows Firewall/Standard Profilehide
Policy Setting Comment
Windows Firewall: Protect all network connections Enabled

System/Logonhide
Policy Setting Comment
Always wait for the network at computer startup and logon Enabled

User Configuration (Enabled)hide
No settings defined.


What we're seeing is that on many workstations the XP firewall remains
on when they are booted up on the domain, until you run "gpupdate
/force" at which point the firewall switches off.

If you run "gpresult" before running the gpupdate /force Windows shows
the GPO as being applied.

Does anyone have any suggestions please?

We have what I would consider to be a normal, flat network, single
subnet with a 2003 R2 DHCP server i.e. nothing unusual to my mind.

Thanks in advance.
Reply With Quote
  #2 (permalink)  
Old 04-05-2008, 08:23 PM
Meinolf Weber
 
Posts: n/a
Re: XP Firewall GPO not applying at startup

Hello usenet,

Check out this one:
Computer Configuration - Administrative Templates - Network - Network Connections
- Prohibit use of Internet Connection Firewall on your DNS domain

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm

> I have the following GPO applied to an OU containing our workstations:
>
> Computer Configuration (Enabled)hide
> Policieshide
> Windows Settingshide
> Security Settingshide
> Windows Firewall with Advanced Securityhide
> Global Settingshide
> Policy Setting
> Policy version Not Configured
> Disable stateful FTP Not Configured
> Disable stateful PPTP Not Configured
> IPsec exempt Not Configured
> IPsec through NAT Not Configured
> Preshared key encoding Not Configured
> SA idle time Not Configured
> Strong CRL check Not Configured
> Domain Profile Settingshide
> Policy Setting
> Firewall state Off
> Inbound connections Not Configured
> Outbound connections Not Configured
> Apply local firewall rules Not Configured
> Apply local connection security rules Not Configured
> Display notifications Not Configured
> Allow unicast responses Not Configured
> Log dropped packets Not Configured
> Log successful connections Not Configured
> Log file path Not Configured
> Log file maximum size (KB) Not Configured
> Connection Security Settingshide
> Administrative Templateshide
> Policy definitions (ADMX files) retrieved from the local
> machine.Network/Network Connections/Windows Firewall/Domain
> Profilehide
> Policy Setting Comment
> Windows Firewall: Protect all network connections Disabled
> Network/Network Connections/Windows Firewall/Standard Profilehide
> Policy Setting Comment
> Windows Firewall: Protect all network connections Enabled
> System/Logonhide
> Policy Setting Comment
> Always wait for the network at computer startup and logon Enabled
> User Configuration (Enabled)hide
> No settings defined.
> What we're seeing is that on many workstations the XP firewall remains
> on when they are booted up on the domain, until you run "gpupdate
> /force" at which point the firewall switches off.
>
> If you run "gpresult" before running the gpupdate /force Windows shows
> the GPO as being applied.
>
> Does anyone have any suggestions please?
>
> We have what I would consider to be a normal, flat network, single
> subnet with a 2003 R2 DHCP server i.e. nothing unusual to my mind.
>
> Thanks in advance.
>



Reply With Quote
  #3 (permalink)  
Old 04-05-2008, 08:23 PM
Meinolf Weber
 
Posts: n/a
Re: XP Firewall GPO not applying at startup

Hello usenet,

Check out this one:
Computer Configuration - Administrative Templates - Network - Network Connections
- Prohibit use of Internet Connection Firewall on your DNS domain

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm

> I have the following GPO applied to an OU containing our workstations:
>
> Computer Configuration (Enabled)hide
> Policieshide
> Windows Settingshide
> Security Settingshide
> Windows Firewall with Advanced Securityhide
> Global Settingshide
> Policy Setting
> Policy version Not Configured
> Disable stateful FTP Not Configured
> Disable stateful PPTP Not Configured
> IPsec exempt Not Configured
> IPsec through NAT Not Configured
> Preshared key encoding Not Configured
> SA idle time Not Configured
> Strong CRL check Not Configured
> Domain Profile Settingshide
> Policy Setting
> Firewall state Off
> Inbound connections Not Configured
> Outbound connections Not Configured
> Apply local firewall rules Not Configured
> Apply local connection security rules Not Configured
> Display notifications Not Configured
> Allow unicast responses Not Configured
> Log dropped packets Not Configured
> Log successful connections Not Configured
> Log file path Not Configured
> Log file maximum size (KB) Not Configured
> Connection Security Settingshide
> Administrative Templateshide
> Policy definitions (ADMX files) retrieved from the local
> machine.Network/Network Connections/Windows Firewall/Domain
> Profilehide
> Policy Setting Comment
> Windows Firewall: Protect all network connections Disabled
> Network/Network Connections/Windows Firewall/Standard Profilehide
> Policy Setting Comment
> Windows Firewall: Protect all network connections Enabled
> System/Logonhide
> Policy Setting Comment
> Always wait for the network at computer startup and logon Enabled
> User Configuration (Enabled)hide
> No settings defined.
> What we're seeing is that on many workstations the XP firewall remains
> on when they are booted up on the domain, until you run "gpupdate
> /force" at which point the firewall switches off.
>
> If you run "gpresult" before running the gpupdate /force Windows shows
> the GPO as being applied.
>
> Does anyone have any suggestions please?
>
> We have what I would consider to be a normal, flat network, single
> subnet with a 2003 R2 DHCP server i.e. nothing unusual to my mind.
>
> Thanks in advance.
>



Reply With Quote
  #4 (permalink)  
Old 04-07-2008, 04:15 AM
Bruce Sanderson
 
Posts: n/a
Re: XP Firewall GPO not applying at startup

Windows XP does not have the "Windows Firewall with Advanced Security. Most
of the settings in Computer Configuration, Policies, Windows Settings,
Security Settings, Windows Firewall with Advanced Security settings will be
ignored by Windows XP SP2 computers.

The settings in Computer Configuration, Administrative Templates, Network,
Network Connections, Windows Firewall are for managing the firewall on
Windows XP SP2 computers.

Whether the "Domain" or "Standard" "Profile" will be applied depends on some
DNS settings - this is explained in the article at
http://technet.microsoft.com/en-ca/l.../bb878049.aspx.

The experience we had with this when we initially configured the XP Firewall
via GPO is that the XP workstations did not initially correctly determine
whether they were connected to the "managed" (Domain) network or not and
selected the "Standard Profile" even when connected to the office (managed)
network. However, after several restarts, they made the correct
determination and the "Domain Profile" was correctly applied when they were
actually connected to the in office network and the "Standard Profile" when
they were not (e.g. laptops in use out of the office). Unfortunately, we
were never able to determine exactly what was causing the incorrect firewall
selection, but the problem went away by itself after the computers were
restarted several times.

The command

netsh firewall show currentprofile

reports whether the "Domain" or "Standard" profile is in use.

--
Bruce Sanderson
http://members.shaw.ca/bsanders

It is perfectly useless to know the right answer to the wrong question.



"Usenet" <usenet@nospam.please> wrote in message
news:usenet-35656D.19134905042008@softbank060082049208.bbtec.n et...
>I have the following GPO applied to an OU containing our workstations:
>
> Computer Configuration (Enabled)hide
> Policieshide
> Windows Settingshide
> Security Settingshide
> Windows Firewall with Advanced Securityhide
> Global Settingshide
> Policy Setting
> Policy version Not Configured
> Disable stateful FTP Not Configured
> Disable stateful PPTP Not Configured
> IPsec exempt Not Configured
> IPsec through NAT Not Configured
> Preshared key encoding Not Configured
> SA idle time Not Configured
> Strong CRL check Not Configured
>
> Domain Profile Settingshide
> Policy Setting
> Firewall state Off
> Inbound connections Not Configured
> Outbound connections Not Configured
> Apply local firewall rules Not Configured
> Apply local connection security rules Not Configured
> Display notifications Not Configured
> Allow unicast responses Not Configured
> Log dropped packets Not Configured
> Log successful connections Not Configured
> Log file path Not Configured
> Log file maximum size (KB) Not Configured
>
> Connection Security Settingshide
> Administrative Templateshide
> Policy definitions (ADMX files) retrieved from the local
> machine.Network/Network Connections/Windows Firewall/Domain Profilehide
> Policy Setting Comment
> Windows Firewall: Protect all network connections Disabled
>
> Network/Network Connections/Windows Firewall/Standard Profilehide
> Policy Setting Comment
> Windows Firewall: Protect all network connections Enabled
>
> System/Logonhide
> Policy Setting Comment
> Always wait for the network at computer startup and logon Enabled
>
> User Configuration (Enabled)hide
> No settings defined.
>
>
> What we're seeing is that on many workstations the XP firewall remains
> on when they are booted up on the domain, until you run "gpupdate
> /force" at which point the firewall switches off.
>
> If you run "gpresult" before running the gpupdate /force Windows shows
> the GPO as being applied.
>
> Does anyone have any suggestions please?
>
> We have what I would consider to be a normal, flat network, single
> subnet with a 2003 R2 DHCP server i.e. nothing unusual to my mind.
>
> Thanks in advance.


Reply With Quote
Reply

  { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Microsoft > Windows Server


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 01:04 PM.


Powered by vBulletin, Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0 ©2007, Crawlability, Inc.
© 1999-2008 mindfrost82.com v11.0


Sponsors:
Credit Cards | Loans | Mortgage | Credit Cards | Home Loan



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114