Solved

Enable XP Firewall remotely

Posted on 2004-08-06
5
172 Views
Last Modified: 2013-12-04
Group Policy has a way of not using the xp firewall when on the domain.
before you set this setting, you can tun the firewall on, then after you apply this and they connect to the domain, it disables the firewall only when connected to the domain.  this way laptops are protected when connected at home on DSL or at airports.

I need a way to enable the xp firewall remotely and apply the above policy.  It would be a lot of work to visit all laptops we have.

you can enable the xp firewall through gpo, but it cancels out the "prohibit use of xp firewall while on domain".
can't have that...

THanks,
Charles
0
Comment
Question by:chaldz
  • 2
5 Comments
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 125 total points
ID: 11741577
Service pack 2 for XP will enable the FW by default- even on the lan... but it's not "concrete" in this article
http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/sp2netwk.mspx#XSLTsection130121120120

These are the old (xp sp1) setting definitions
The firewall turns off when a VPN connection is made BTW... so dsl/cable users are without a fw if you rely on XP ICF... ZoneAlarm is free, and a slightly better firewall
http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/xpmanaged/33_xpape.mspx

Prohibit Use of Internet Connection Firewall on your DNS domain network (enabled)
 If you enable this policy setting, Internet Connection Firewall cannot be enabled or configured by users (including administrators), and the Internet Connection Firewall service cannot run on the computer. The option to enable the Internet Connection Firewall through the Advanced tab is removed. In addition, the Internet Connection Firewall is not enabled for remote access connections created through the Make New Connection Wizard.
 
Prohibit Use of Internet Connection Firewall on your DNS domain network (disabled or not configured)
If you disable this policy setting or do not configure it, the Internet Connection Firewall is disabled when a LAN connection or virtual private network (VPN) connection is created, but users can use the Advanced tab in the connection properties to enable it. The Internet Connection Firewall is enabled by default on the connection for which Internet Connection Sharing is enabled. In addition, remote access connections created through the Make New Connection Wizard have the Internet Connection Firewall enabled.

These are the regisrty entries that change when the firewall is enabled through the NIC properties (not sure if it's just one or all of them)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG
Seed REG_BINARY 4F8CAF88FA1D3780CD404F3EB568E0C1FF7AC2D9CB7DE82C6661593EFEB33B0AF7CD724DEF57E72971C448554D500FDD1C9A594691EAB731051AF604DC1C6893D11ED09B6CCDE71C509031CBFDBBE6DB (enabled)
B5F1C06FAD9E95CF6B51416886780E1F7A0DEF91439DB5378EC8361FE62972B22E7D8EB12BE79F8F265A08B97BF2F4E666DA3017F8D94BF9ED72BBE9E4DD11C3F934640A6CCD40D5D8CEA865DD5AF285 (disabled)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
RefCount REG_DWORD 0x00000001 [1] (disabled)
RefCount REG_DWORD 0x00000002 [2] (enabled)
HKEY_USERS\S-1-5-21-1275210071-854245398-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count
HRZR_EHAPCY REG_BINARY 1f 01 00 00 06 00 00 00 40 13 ea ca 37 7c c4 01 (enabled)
HRZR_EHAPCY REG_BINARY 1f 01 00 00 07 00 00 00 30 66 fc 0a 39  7c c4 01 (disabled)
HRZR_EHAPCY:APCN.PCY REG_BINARY 1f 01 00 00 06 00 00 00 40 13 ea ca 37 7c c4 01  (enabled)
HRZR_EHAPCY:APCN.PCY REG_BINARY 1f 01 00 00 07 00 00 00 30 66 fc 0a 39 7c c4 01  (disabled)
HKEY_USERS\S-1-5-21-1275210071-854245398-1957994488-1003\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0
MRUListEX REG_BINARY 00 00 00 00 03 00 00 00 01 00 00 00 02 00 00 00 ff ff ff ff (enabled
MRUListEX REG_BINARY 03 00 00 00 03 00 00 00 01 00 00 00 02 00 00 00 ff ff ff ff (disabled)

And these changed when I disabled it again:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent
[Default] REG_DWORD 0x00000017 (23) (enabled)
[Default] REG_DWORD 0x00000018 (24) (disabled)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent
[Default] REG_DWORD 0x00000017 (23) (enabled)
[Default] REG_DWORD 0x00000018 (24) (disabled)
-rich
0
 
LVL 38

Expert Comment

by:Rich Rumble
ID: 13958824
I think I answered the question.
-rich
0

Featured Post

Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Vulnerability scanning tools! 5 122
Group Policy, Server 2012: Remove local Administrator users on Workstations, not Servers 3 42
Ransome Ware Question 10 151
PCI compliance 16 33
This is a guide to the following problem (not exclusive but here) on Windows: Users need our support and we supporters often use global administrative accounts to do this. Using these accounts safely is a real challenge. Any admin who takes se…
Our Group Policy work started with Small Business Server in 2000. Microsoft gave us an excellent OU and GPO model in subsequent SBS editions that utilized WMI filters, OU linking, and VBS scripts. These are some of experiences plus our spending a lo…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question