Jump to content

Recommended Posts

Posted

Adding my first 2008 R2 DC to my domain my 2003 DC's don't have the microsoft firewall enabled should I leave it enabled on the 2008 R2 DC or not?

 

Clients all have firewall enabled.

 

Ben

Posted
Yes I would, just because it is inside the network does not make it safe and the firewall will add an extra little bit of protection. Server2k8 is quite good at opening up ports that it needs for its own services and many other thrid party server applications are now firewall aware and will open up their required ports on install. There is the occational program that needs an exception added manually but this is a small hassle compared to reinstalling the whole thing if it gets comped by a worm loose inside the network.
Posted

I have the firewall enabled on all our 2k8 Servers, Extra bit of protection especially these days with the amount of viruses people seem to aquire... just to be on the safe side.

 

As Synack Said, Server 2k8 is pretty good at opening the ports it requires.

 

James

Posted
Windows firewall, waste of time, I always turn them off, cause too many problems

 

likewise, did that before.. but seriously they don't seem to upset things in 2k8

Posted

Have it enabled on my 2008 and 2008R2 boxes. Never did on 2003, but having had a worm, and seen how many viruses get picked up by Sophos on kids and staff USB drives I now prefer to have that little extra protection just in case another Worm gets in....

 

Did have one issue where the Ports needed for Netlogon replication didn't get opened on our 2008R2 DC box (2008 DC was okay though). Didn't spot it for a while, when I did though it explained a few things....

 

Oh, and another issue I had was that when I used GPOs to control the server firewalls it went a bit wrong and I had total lockdown. A bit of googling turned up similar problems, and the general consensus was to manually allow things on each server rather than via GPO, worked fine ever since. Can't remember what these extra ports were now, as mentioned above most Apps tend to open the ports themselves on install, and Windows does if adding roles/features.

Posted

We keep them enabled. If you have it enabled it slows the confikr worm right down.

 

As others have said its much better regarding ports than previous versions

Posted
Agree with all the above, keep it on. Especially with Conficker about ..... our biggest mistake here was turning it off and we got infected with it!
Posted
Never had a problem with Windows Firewall, client or server. It tends to be the third party firewalls that are a bit overzealous. Definitely enabled.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...