Jump to content

Recommended Posts

Posted

Hi all i'm having continual problems connecting to machines remotely on our network etc because of the xp firewall, do otyhers have the same issues? do you turn it off internally? any thoughts or advice please?

 

as always thanks in advance.

Posted
is there any tool i can get that will do en-masse ? i came across one recently but can't find it now and it only worked on a few machines
Posted
We do it as part of the image I'm afraid. Haven't really looked into any other way of doing it, and as a my wife says, I shouldn't be doing this as I'm on holiday.
Posted

Off here. Its too much work to be reconfiguring ports on the individual PCs. Besides, thats what our Cisco router, RBC firewall, AV software etc is for.

I have it on at home though, even though I have a nice Netgear router which does alot for me anyway.

Posted
Thanks all had never managed to find it gpo before as its listed under networks, have made the neccassary changes and now just need to wait for the gpudate to take effect *tried with secops update but as the firewall is switched on it doesn't work.
Posted

I keep it on and create exceptions for programs that need it, theres only about 3 or 4

 

Theres not much point having it on though as its virtually useless as a firewall, and as we have our own and the LEA's its not needed

Posted

Yep ours is off at domain level as we found that it caused problems just trying to add PC's to the Domain!! why that was the case we don't know but as soon as the firewall was off we could join the domain.

 

Also no need for it as our LEA have firewall in place

 

Though will be looking for a hardware firewall solution for when we eventually break away from the LEA

Posted

Experimented with it "on" but it stopped our auditing software from doing what it should ie/auditing!

 

The worst part was that you had to turn it off to allow Mcafee to be pushed out, and then turn it back on again

 

Too much hassle having it on, as has been commented on prior to my message

Posted
Ours is very definately off as well. As somebody previous to this mentioned; we also have a hardware firewall on the edge of our network and the LEA has one as well so theres not a lot of point in having the workstation firewall enabled. All it seems to do when turned on is complicate things.
Posted
We disabled it because A, it buggers about with software like NetSupport School and Sophos and B, your proxy server / internet gateway / main firewall or whatever you want to call it should be enough to keep the nasties out from t'internet.
Posted

I have it ON - causes no problems for me. Just have it so I can access the hard drives. Remember why Microsoft turned it on by default? Melissa.

You can configure it or switch it off using standard GPOs.

Posted

Just realised who has posted this topic 8)

 

There is no way that you need the XP Client Firewall switched on mate. NETLinc provide a two-layered hardware firewall before the connection hits your site and on the newer routers (unsure whether you had been upgraded to 10MB last time we spoke) there is also a thin-firewall solution. Nothing out of the ordinary should be able to hit your local domain through the EMBC and should anything work its way in, there is no way it will be able to communicate back outside the network again.

 

Tom

Posted

Windows Firewall is there for a good reason - to protect your PC in case of attack. If you turn it off you are running the security gauntlet. Most attacks happen by compromising one machine WITHIN your network, then working from there. Bearing in mind, USP pens, Laptops that go home etc. there is more of a risk of compromise in a school than you may think. So if Windows Firewall is turned off on your domain - you - in effect have no protection.

 

Far the best way is to leave it turned on, then use Group Policy to set an exclusion for the program/ports you want to allow access. It is relatively simple to do and easy to manage centrally. You can even browse to find the executable you want to allow access.

Posted

Hmmm.. can't see a link between Melissa and the XP firewall... and there aren't many networks with some kind of Internet link where you can't communicate with the outside world if you're subtle enough.

 

Anyway, everyone tends to have edge firewalling (dedicated f/w boxes, router ACLs, LA f/w or whatever) but the other factor is whether you think machines on your network may be at risk from other machines plugged into your network e.g. laptop picked up worm at home, some box where someone is deliberately trying to hack etc. And if you think that risk is significant would the XP f/w help reduce it?

 

It depends on your network and for me the answers is: There's a bit of a risk, but it won't go away if you turn the XP f/w on.

Posted
It depends on your network and for me the answers is: There's a bit of a risk, but it won't go away if you turn the XP f/w on.

 

But what do you actually gain? Like adent says, it's trivial to configure it centrally with GP and open ports as required.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...