How do you do....it? Thread, Windows XP SP2 firewall policies on Domain in Technical; Just wondering how everyone else does this. We have the Default Domain policy set so that Windows Firewall is turned ...
-
24th September 2006, 06:06 PM #1 Windows XP SP2 firewall policies on Domain
Just wondering how everyone else does this. We have the Default Domain policy set so that Windows Firewall is turned of on our domain. I have been reading in depth on this today and reading about all the various firewall options.
How have you got your set up?
DO you have it enabled and the configure the policy settings?
Is your disabled like ours?
Your thoughts and suggestions please. :dontknow:
-
-
IDG Tech News
-
24th September 2006, 06:21 PM #2 Re: Windows XP SP2 firewall policies on Domain
I keep it turned off personally. Makes life easier all round.
-
-
24th September 2006, 06:34 PM #3 Re: Windows XP SP2 firewall policies on Domain
I keep it turned off also. Make life much more easy in the long run.
-
-
24th September 2006, 06:47 PM #4 Re: Windows XP SP2 firewall policies on Domain
You need the new ADM templates (either W2K3 SP1 or XP SP2) to control the firewall settings.
I disable it.
-
-
24th September 2006, 07:24 PM #5 Re: Windows XP SP2 firewall policies on Domain
We have it disabled, too. Workstations aren't directly connected to the internet and the chances of them suffering an attack internally that the firewall could handle anyway is fairly non-existant.
-
-
24th September 2006, 10:10 PM #6 Re: Windows XP SP2 firewall policies on Domain
-
-
24th September 2006, 10:25 PM #7 Re: Windows XP SP2 firewall policies on Domain
Turned off. It saves me having to allow various differnt ports for certain software i.e NetSupport Manager on each machine. besides, your domain firewall is supposed to protecting your LAN. The Windows one is fine for home and on the road use, but not in your school. A good AV setup and domain firewall should be all you need.
-
-
24th September 2006, 11:46 PM #8 Re: Windows XP SP2 firewall policies on Domain
I have it disabled on workstations but laptops have it enabled when not connected to the network (there is a setting to do this).
-
-
25th September 2006, 07:15 AM #9 Re: Windows XP SP2 firewall policies on Domain
I'd like to vote for on just to buck the trend. I had it turned off for the last couple fo years but decided to switch it on as I have some pupils who connect to the network with their laptops.
Easy enough to get working.
Sophos Remote Management, VNC and Browsecontrol are the only ones I have needed to open up but mines a nice quiet network.
-
-
25th September 2006, 08:32 AM #10 Re: Windows XP SP2 firewall policies on Domain
Same as Simcfc73, changed it this year, use a netsh command during sysprep to set exceptions having modified the netfw.inf
-
-
25th September 2006, 10:33 AM #11 Re: Windows XP SP2 firewall policies on Domain
On. If a nasty worm/virus does get onto your network (yes, I know AV should pick it up but you never know...), then your PCs are still protected. It's really easy to configure it, so why not!
-
-
25th September 2006, 11:10 AM #12 Re: Windows XP SP2 firewall policies on Domain

Originally Posted by
ajbritton On. If a nasty worm/virus does get onto your network (yes, I know AV should pick it up but you never know...), then your PCs are still protected. It's really easy to configure it, so why not!
Yes, but then it is in your network. And with XPs firewall only being one way (inbound) then it would be free to escape an infected PC anyway! Besides, remember Blaster? The XP firewall was like a chocolate fireguard in that instance.
-
-
25th September 2006, 11:27 AM #13 Re: Windows XP SP2 firewall policies on Domain
Remeber Blaster? I still have nightmares of turning up to work that morning :LOL:
-
-
25th September 2006, 01:25 PM #14 Re: Windows XP SP2 firewall policies on Domain
It took me the better part of two weeks to get that bastard and Nachi cleared from our network. Fun :\
-
-
25th September 2006, 05:07 PM #15 Re: Windows XP SP2 firewall policies on Domain
As I eluded to in another thread. I have a system for combating worms at the firewall.
http://www.edugeek.net/index.php?nam...ewtopic&t=4314
Even so, as Dos_Box says, the Windows firewall will not help you in a Blaster/Nachi situation. This is because there are default exceptions for the RPC and Windows networking ports (137-139 and 445). You can't block these ports on the client in a domain enviroment because AD ceases to function.
The only way you can stop them is by blocking them before they enter your network and by keeping your machines patched and up to date (although Microsofts release policy leaves a lot to be desired).
The only other obvious infection path way I can think of that I haven't got a solution for is laptops coming off and on the network.
-
SHARE: 
Similar Threads
-
By badsurname in forum Windows
Replies: 29
Last Post: 18th January 2008, 02:30 PM
-
Replies: 5
Last Post: 20th September 2007, 09:15 AM
-
By Mintsoft in forum Windows
Replies: 3
Last Post: 22nd March 2006, 09:59 AM
-
Replies: 2
Last Post: 22nd February 2006, 12:30 AM
-
By GrumbleDook in forum Windows
Replies: 16
Last Post: 31st August 2005, 12:54 PM
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules