Jump to content

Recommended Posts

Posted
What do people think of using the Windows Firewall on Windows 10 PCs ? Seems like a load of trouble for little benefit. I'm normally wary of removing layers of security, but I'm struggling to come up with a scenario where it will help us as far as networked PCs behind our firewall go.
Posted

Not sure what the "lots of trouble" aspect is? There's very few network based programs nowadays that need much opening, and for most programs that need it they give you all the ports. And it's internal access really that helps, if one machine gets compromised etc it's not going to spread internally etc think conficker wise from XP days.

 

Seems like trying to cut corners for no real reason if I'm honest.

 

Steve

Posted
I am with @Steve21 here, you would not remove your North/ South firewall. So why would you remove your east/ west firewall? Its the only thing that will slow up the spread of malicious software/ code around your network (that and ACL's) I would think carefully before deciding to ditch it....
Posted

I've not found it to be trouble, not much needs to be opened apart from defaults, only thing I add is minecraft.

 

At least you can have one setting for on domain, and one for public when laptop is at home.

Posted

Not really much trouble.

 

It's completely manageable by GPO, if you're introducing it and a bit worried about issues, just nominate a group of machines to be guinea-pigs and just switch it on there.

 

Test, test, test and then introduce to the rest of your domain/estate.

Posted
How much it would help while on domain is a question though. You'd probably be allowing file sharing, so a virus with admin creds can easily spread, and remote desktop, so that won't help much. Could start restricting by IP more, only accept connections from server/ITS computers.
Posted
How much it would help while on domain is a question though. You'd probably be allowing file sharing, so a virus with admin creds can easily spread, and remote desktop, so that won't help much. Could start restricting by IP more, only accept connections from server/ITS computers.

 

That's kind of my thinking. Most stuff looking to maliciously spread will be using conventional routes that will be open on a firewall anyway. Windows 10 has pretty good mitigation built in too so situations like Confiker should be in the rear view mirror.

 

We're currently not running the firewall on PCs but are on servers, but even then we've had to turn it off on a couple of servers as we just can't get some stuff working through it.

 

I'm planning on trying to get it working again on PCs, just wanted to see what others were doing to see where I should put it on the priority list.

Posted
I have a question about this who is connecting their users to a file share with an admin account or logging on to client computers as an admin? Or conversely connecting to a users file store logged on with an admin account? Also RDP from client computers to servers outside of IT Services and on data center network? Really?
Posted (edited)

If you're having any problems getting a program to work just turn on audit mode, and/or the pop-up alerts when something gets blocked. Then you'll see what gets hit/blocked.

 

With Ransomware etc as it is there's really no reason not to be using a firewall on clients in this day and age (Server side ok that could be more problematic but getting clients tested shouldn't be)

 

Not really sure what the argument about virus with admin logins is as 90% of ransomware doesn't use admin rights to spread/run so that's rather a null point imo (ok just an example with ransomware and there's "others" but point still provided :p)

 

Steve

Edited by Steve21
Posted (edited)

Well I think any malware with access to a domain admin account would be serious trouble firewall or no. We've got a few users on their PCs with local admin access due to carppily written software, but no one uses domain admin access to log into their PCs, not even us.

 

The best protection against malware is not giving users local admin access.

 

But thanks everyone for your thoughts, very useful.

Edited by dcwhitworth
Posted
I have a question about this who is connecting their users to a file share with an admin account or logging on to client computers as an admin? Or conversely connecting to a users file store logged on with an admin account? Also RDP from client computers to servers outside of IT Services and on data center network? Really?

 

I was more thinking of default C$ etc access to client computers.

 

People with small networks.

Posted (edited)
How much it would help while on domain is a question though.

Most stuff looking to maliciously spread will be using conventional routes that will be open on a firewall anyway. Windows 10 has pretty good mitigation built in too so situations like Conficker should be in the rear view mirror.

 

Endpoint Isolation with the Windows Firewall

 

Over the last few weeks, I’ve had conversations with several individuals around mitigating lateral movement in a Windows environment. In all of these cases, I was surprised to learn that these defenders were not using the native Windows Firewall as one of their defense-in-depth layers. This was curious to me as the firewall is both present by default and is one of the easiest ways to limit remote access to many commonly-abused services.

 

This post is going to focus on using the Windows Firewall for isolating and securing endpoints in an Active Directory environment. The goal is to limit the potential attack surface of endpoints by limiting access to potentially exploitable services, require IPSEC authentication to management services, and provide additional encryption to services which rely on plaintext or weak ciphers. The configurations listed in this post should be immediately deployable in a production environment and ultimate make our adversary’s lateral movement attempts that much more frustrating.

 

An important note: you should go watch Jessica Payne’s ‘Demystifying the Windows Firewall’ talk from Ignite 2016. Most of the content in this post is simply a rehash of the best practices and strategies that she has outlined in her presentation. Her talk is the reference for the Windows Firewall.

 

Seriously, go watch it right now.

 

Demystifying the Windows Firewall – Learn how to irritate attackers without crippling your network (Slides)

 

In 2016, host based firewalls are not optional in a Cybersecurity strategy. Windows comes with a built in and powerful firewall, however the Windows Firewall has a reputation for being difficult to troubleshoot and manage, which leads to it being turned off in most organizations and not well understood. We'll walk through the ins and outs of the Windows Firewall, the attacks it prevents, strategies for managing firewall profiles in complex enterprise environments, planning a rollout that doesn't break everything and troubleshooting when everything does break. We'll also dive into the misunderstood magic of IPsec, showcasing the capabilities available to your customer (identify based firewall rules!) if they embrace the Windows solution, how to unravel the mysteries of “why is my IPsec negotiation failing?” and when and when not to use IPsec.

 

 

https://twitter.com/RoganDawes/status/1062945724072103936

 

9WJuNA.png

 

Microsoft recommend keeping the Windows Firewall enabled for all domain/enterprise devices. See their SECCON Framework for more details.

 

Introducing the security configuration framework

 

Level 1 is the minimum security configuration for an enterprise device. Microsoft recommends the following configuration for level 1 devices.
Edited by Arthur
  • Thanks 1
Posted (edited)
I am not sure why you would want to disable the Windows Firewall. You are opening up yourself to many more security vulnerabilities. It should work and not cause any problems out of the box for the majority of things. If you are having trouble with it is it possible you have a GPO which is mucking the settings up perhaps? Edited by CCCSecMan
Posted
If you're having any problems getting a program to work just turn on audit mode, and/or the pop-up alerts when something gets blocked. Then you'll see what gets hit/blocked.

 

Or look in Event Viewer?

Posted
Which requires logging/audit to be turned on as mentioned :p

 

Steve

 

Interesting, never specifically turned on, or remember doing it, auditing for firewall or applications.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...