chrisprice Posted January 26, 2022 Posted January 26, 2022 Hi guys, Hoping someone can help me to answer a seemingly stupid question. I work in a sixth form college in Leicester and we're working on getting our Windows Firewall enabled on client devices. The group policy I was building was going swimmingly, until I tried to roll it out to a set of machines (typical). As soon as the firewall was enabled, user policies will not pull down from our DC's. Computer policies seem to be ok, but we get an error when trying a gpupdate for the user policy. We have our firewall default action for all inbound/outbound to block, unless it matches a rule of ours. I have added the necessary ports for DC client communication, as recommended by Microsoft, as well as the necessary group policy ports, but still seems to be a problem. DNS is also opened and all other DC communication is ok, nothing else seems to be an issue. I used a lot of the preset rules from Microsoft to allow the necessary ports anyway, so I really dont see what I'm missing. I've been through all the Microsoft tables and checked every port, yet still no luck. Anyone got any ideas? Am I missing anything? For obvious reasons I wont screenshot our firewall rules, but happy to answer questions if needed. Thank you for any ideas Chris
HPlum78 Posted January 26, 2022 Posted January 26, 2022 Is this only happening on the group of machines you have applied the new policy to? Just for sanity sake would be worth checking! Is there anything in the gpresult output that could be useful or in the event logs? It's broad so is hard to pin it down from just that screen grab...
chrisprice Posted January 26, 2022 Author Posted January 26, 2022 Hi, Thanks for the reply. Yes it only happens on the group of computers to which I apply the policy - currently only my pc though as I rolled it out to an office and none of their network drives were mapped Gpresult doesn't really tell us much apart from the fact it cant apply the user policies due to the above. Event logs just give us the same error as the cmd window, so its frustrating to diagnose. I tried turning off firewall on my machine and the user policy works instantly - no issues. Chris
Steve21 Posted January 26, 2022 Posted January 26, 2022 What Ports/rules have you actually done, as most likely you are just missing one in the list, even something silly like it being inbound rather than outbound etc Steve
HPlum78 Posted January 26, 2022 Posted January 26, 2022 Yeah its going ro be something daft as @Steve21 suggest.
Davit2005 Posted January 26, 2022 Posted January 26, 2022 Surely windows firewall would not block outgoing ports for active directory. Firewalls generally deal with incoming traffic but I have known windows firewall to block icmp ping replies before now. There are about 20 or so ports for active directory some UDP and some ranges. I'll try and dig them out.
Steve21 Posted January 26, 2022 Posted January 26, 2022 Surely windows firewall would not block outgoing ports for active directory. OP said they set their default to block for in/out unless they've added a rule in, rather than doing a standard merge etc, thus probably missing a bit Steve
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now