Jump to content

Recommended Posts

Posted

It has been one of those days ...

 

We have discovered that Windows Firewall has decided to block the RPC server and stop certain connections (unless the user logging on is a member of the local admin group). THis includes failing to load GPOs properly.

 

What methods do people use for turning off the firewall? (simplest solution in the short term IMHO)

 

Has anyone come across anything similar?

 

Tony

Posted

Just turn off the Windows Firewall using a GPO!

 

You can even set it to turn the firewall back on when the client is not connected to the domain!

 

Easy as...

 

BTW - you may need to update your ADMs to those that come with XP SP2.

Posted

netsh firewall /? should give you all the command line options for the Windows Firewall. I use this method for adding ports & exceptions quickly. I think you can do a complete reset of the firewall this way.

 

Only downside being, if the firewall's gone crazy, you may have to run it locally on each comp...

Posted
@Dos_Box: It might be useful to start a list of software which is not compatible with the XP SP2 firewall. For myself, I have left the firewall enabled without any difficulties apart from having to open the occasional port or three.
Posted

If you have a firewall between your network and the outside world, there is no reason to switch the firewall on at client level.

 

Using the GPO settings, you have it re-enable itself when offsite and jobs a good'n! :)

Posted
Surely firewalls on individual PCs will help prevent the spread of viruses/worms within the site, should a silly member of staff be daft enough to bring one in on a floppy..?
Posted
Surely firewalls on individual PCs will help prevent the spread of viruses/worms within the site, should a silly member of staff be daft enough to bring one in on a floppy..?

 

But you properly maintained AV software will kill this anyway!

Posted
Surely firewalls on individual PCs will help prevent the spread of viruses/worms within the site, should a silly member of staff be daft enough to bring one in on a floppy..?

 

But you properly maintained AV software will kill this anyway!

 

And this is one of the apps that is being blocked from installation by the firewall.

 

Bloody typical really ... the firewall stops people connecting to your machine ... people like the SysAdmin ... and installing potentially harmful software ... like AV software.

 

*sigh*

Posted
@Ric : I take the view that the local network is now potentially a hostile environment. Once the network spreads school-wide, it's very difficult to control what is connected to it. Staff bring in laptops which may or may not have up to date AV on them. I figure the best I can do is to implement every security feature available to me; AV, WSUS and the firewall.
Posted

I'd have to agree with abj - not that I'm saying either argument is correct...

 

It's just what works for their particular network, and way of doing things - unless you have no firewall on at all ...anywere lol ;)

 

in abj's defense - have client f/w's on is handy - not against viruses, but other sorts of malicious things like spyware and other nasties.

 

Also helps limit the chances of a user having some sort of program in their home dir (brought in by whatever means) and used against the system - at least with a client firewall, you can prevent a app from doing anything :)

 

Just my two cents - i have more pressing matters tho (see a lovely possible-DNS-related-problem topic in a few moments appearing)...

 

Regards

Nath.

Posted

You guys need a large pointy stick to prod and hit these people with!

 

It's your job to configure the AV updates so you just need a way to make sure that it's done automagically.

Posted
Surely firewalls on individual PCs will help prevent the spread of viruses/worms within the site, should a silly member of staff be daft enough to bring one in on a floppy..?

 

Not really. The Windows firewall is one way only; incoming. Which is negated by said infected floppy\CD.

Posted
Surely firewalls on individual PCs will help prevent the spread of viruses/worms within the site, should a silly member of staff be daft enough to bring one in on a floppy..?

 

Not really. The Windows firewall is one way only; incoming. Which is negated by said infected floppy\CD.

 

A fair point, but the firewalled PCs would have extra protection against rogue laptops which may be connected to the network from time to time. It only takes one careless member of staff...

Posted
Surely firewalls on individual PCs will help prevent the spread of viruses/worms within the site, should a silly member of staff be daft enough to bring one in on a floppy..?

 

Not really. The Windows firewall is one way only; incoming. Which is negated by said infected floppy\CD.

 

? what about the ol' window that pops up asking whether to allow program xyz.exe to access the internet? (the one that has the [unblock] button on it and is dark-blue colour)

 

Isn't that part-and-parcel of Windows Firewall?

 

It only takes one careless member of staff...

 

So true - dont we all know it lol

 

Just my two cents :)

 

Nath.

Posted

@Tosca: Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall

 

You have 2 profiles - Domain Profile for when you are hooked up to the domain and Standard Profile for the rest of the time.

 

Get the PolicySetting.xls file from MS (mentioned above) - invaluable for finding these settings!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...