WUGNET, the Windows User Group Network
Your Complete Resource Center for "The Best" in Shareware, Computing Tips and Support, Windows Industry News... and much more!
Home Forums Shareware Windows Tips Hot Offers FREE Newsletters Arcade Contact Us About Partners
Search WUGNET: RSS Feeds RSS Feeds Advertise with WUGNET    |    Shareware eBooks
HomeHome FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

XP Firewall - updating client rules by netfw.inf, Group Po..

 
   Home -> Windows Other -> Group Policy RSS
Next:  RE  
Author Message
Barkley Bees

External


Since: Feb 07, 2008
Posts: 30



(Msg. 1) Posted: Thu Aug 14, 2008 3:12 am
Post subject: XP Firewall - updating client rules by netfw.inf, Group Policy or other?
Archived from groups: microsoft>public>win2000>group_policy, others (more info?)

Here's an XP client Firewall and Group Policy question I have.

Scenario:

We have recently recreated our internal XP client image and this image
includes some new and updated Firewall rules with specific programs and
ports allowed (defined in - "netfw.inf"). The majority of our client
computers are still running on the old image which does not include these
new allowed ports and programs.

To rectify this for clients using the old image, I am thinking to simply
define these same allowed programs and ports in Group Policy. That said, I
am concerned as to what effect this may have on Computers based on the new
image that have these rules predefined locally in the netfw.inf (possible
conflicts that may cause the Windows Firewall/ICF service to hang, the two
rules to nullify each other, etc).

I suppose the only way to be sure is to test it out (which I will) but I am
just curious if anyone has tried any similar action (specifying client
firewall rules in Group Policy that already exist locally on some machines).

Can anyone recommend a better approach? Possibly replacing the "netfw.inf"
on all the old image based systems? Appreciate any feedback. Thanks.
Back to top
Login to vote
Florian Frommherz [MVP]

External


Since: Feb 28, 2008
Posts: 67



(Msg. 2) Posted: Thu Aug 14, 2008 3:12 am
Post subject: Re: XP Firewall - updating client rules by netfw.inf, Group Policy [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Howdie!

Barkley Bees wrote:
> To rectify this for clients using the old image, I am thinking to simply
> define these same allowed programs and ports in Group Policy. That said, I
> am concerned as to what effect this may have on Computers based on the new
> image that have these rules predefined locally in the netfw.inf (possible
> conflicts that may cause the Windows Firewall/ICF service to hang, the two
> rules to nullify each other, etc).

From what I know about the netfw.inf and its usage is that once the
Firewall reloads the configuration from the file, it puts it into the
registry - and that's the same location where settings made in Group
Policy go. Although not having tested it, I would assume that the
settings won't nullify each other nor bring the firewall service down.
What you can do is

(1) Define Group Policy for other already installed clients
(2) deploy the netfw.inf file and reload filewall configuration (with
netsh command-line)

Either way should work for you.

cheers,

Florian
--
Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
Maillist (german): http://frickelsoft.net/cms/index.php?page=mailingliste
Back to top
Login to vote
Display posts from previous:   
       Home -> Windows Other -> Group Policy All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Categories:
 Windows XP
 Windows Vista
  Windows Other
 Office
 Office Other
 Security
 WinRAR
  • Home |
  • Shareware |
  • Windows Tips |
  • Hot Offers |
  • FREE Newsletters |
  • Arcade |
  • Forums |
  • eBooks |
  • About WUGNET |
  • Partners |
  • Contact

  • WUGNET Privacy Policy |
  • Link to WUGNET