Uraken Posted February 16, 2007 Posted February 16, 2007 Hi all i'm having continual problems connecting to machines remotely on our network etc because of the xp firewall, do otyhers have the same issues? do you turn it off internally? any thoughts or advice please? as always thanks in advance.
webman Posted February 16, 2007 Posted February 16, 2007 We turn it off internally, we don't see any point ihaving it turned on.
beeswax Posted February 16, 2007 Posted February 16, 2007 same as Craig. It causes too many problems otherwise.
Uraken Posted February 16, 2007 Author Posted February 16, 2007 is there any tool i can get that will do en-masse ? i came across one recently but can't find it now and it only worked on a few machines
webman Posted February 16, 2007 Posted February 16, 2007 No idea, CC3 provided us with a GPO to configure ours (ports, exceptions, everything.. but it's easier to just turn it off).
beeswax Posted February 16, 2007 Posted February 16, 2007 We do it as part of the image I'm afraid. Haven't really looked into any other way of doing it, and as a my wife says, I shouldn't be doing this as I'm on holiday.
webman Posted February 16, 2007 Posted February 16, 2007 It's ok beeswax, we won't tell her if you don't
Dos_Box Posted February 16, 2007 Posted February 16, 2007 Off here. Its too much work to be reconfiguring ports on the individual PCs. Besides, thats what our Cisco router, RBC firewall, AV software etc is for. I have it on at home though, even though I have a nice Netgear router which does alot for me anyway.
goodhead Posted February 16, 2007 Posted February 16, 2007 we turn ours off. we found it interfeared with sophos. we control it with GPO
Uraken Posted February 16, 2007 Author Posted February 16, 2007 Thanks all had never managed to find it gpo before as its listed under networks, have made the neccassary changes and now just need to wait for the gpudate to take effect *tried with secops update but as the firewall is switched on it doesn't work.
sidewinder Posted February 16, 2007 Posted February 16, 2007 I keep it on and create exceptions for programs that need it, theres only about 3 or 4 Theres not much point having it on though as its virtually useless as a firewall, and as we have our own and the LEA's its not needed
ChrisH Posted February 16, 2007 Posted February 16, 2007 You can turn it off via: GPO An entry in the RIS answer file Using the netsh command in a script.
SteveT Posted February 16, 2007 Posted February 16, 2007 Off, Off, Off, Off, Off, Off, ............. etc.
Gatt Posted February 16, 2007 Posted February 16, 2007 Yep ours is off at domain level as we found that it caused problems just trying to add PC's to the Domain!! why that was the case we don't know but as soon as the firewall was off we could join the domain. Also no need for it as our LEA have firewall in place Though will be looking for a hardware firewall solution for when we eventually break away from the LEA
cheesypete Posted February 16, 2007 Posted February 16, 2007 Experimented with it "on" but it stopped our auditing software from doing what it should ie/auditing! The worst part was that you had to turn it off to allow Mcafee to be pushed out, and then turn it back on again Too much hassle having it on, as has been commented on prior to my message
tscnmuk Posted February 16, 2007 Posted February 16, 2007 Ours is very definately off as well. As somebody previous to this mentioned; we also have a hardware firewall on the edge of our network and the LEA has one as well so theres not a lot of point in having the workstation firewall enabled. All it seems to do when turned on is complicate things.
john Posted February 16, 2007 Posted February 16, 2007 I am mixed, I have some with it on and some without it on, where its on, its all been configured for Sophos etc via GPOs
Joedetic Posted February 16, 2007 Posted February 16, 2007 We disabled it because A, it buggers about with software like NetSupport School and Sophos and B, your proxy server / internet gateway / main firewall or whatever you want to call it should be enough to keep the nasties out from t'internet.
eean Posted February 16, 2007 Posted February 16, 2007 I have it ON - causes no problems for me. Just have it so I can access the hard drives. Remember why Microsoft turned it on by default? Melissa. You can configure it or switch it off using standard GPOs.
tscnmuk Posted February 21, 2007 Posted February 21, 2007 Just realised who has posted this topic 8) There is no way that you need the XP Client Firewall switched on mate. NETLinc provide a two-layered hardware firewall before the connection hits your site and on the newer routers (unsure whether you had been upgraded to 10MB last time we spoke) there is also a thin-firewall solution. Nothing out of the ordinary should be able to hit your local domain through the EMBC and should anything work its way in, there is no way it will be able to communicate back outside the network again. Tom
DMcCoy Posted February 21, 2007 Posted February 21, 2007 I have it on, just add your rules to group policy for any apps that need access.
adent Posted February 21, 2007 Posted February 21, 2007 Windows Firewall is there for a good reason - to protect your PC in case of attack. If you turn it off you are running the security gauntlet. Most attacks happen by compromising one machine WITHIN your network, then working from there. Bearing in mind, USP pens, Laptops that go home etc. there is more of a risk of compromise in a school than you may think. So if Windows Firewall is turned off on your domain - you - in effect have no protection. Far the best way is to leave it turned on, then use Group Policy to set an exclusion for the program/ports you want to allow access. It is relatively simple to do and easy to manage centrally. You can even browse to find the executable you want to allow access.
PiqueABoo Posted February 21, 2007 Posted February 21, 2007 Hmmm.. can't see a link between Melissa and the XP firewall... and there aren't many networks with some kind of Internet link where you can't communicate with the outside world if you're subtle enough. Anyway, everyone tends to have edge firewalling (dedicated f/w boxes, router ACLs, LA f/w or whatever) but the other factor is whether you think machines on your network may be at risk from other machines plugged into your network e.g. laptop picked up worm at home, some box where someone is deliberately trying to hack etc. And if you think that risk is significant would the XP f/w help reduce it? It depends on your network and for me the answers is: There's a bit of a risk, but it won't go away if you turn the XP f/w on.
ajbritton Posted February 22, 2007 Posted February 22, 2007 It depends on your network and for me the answers is: There's a bit of a risk, but it won't go away if you turn the XP f/w on. But what do you actually gain? Like adent says, it's trivial to configure it centrally with GP and open ports as required.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now