Solved

Disable Firewall through GPO

Posted on 2006-06-29
12
357 Views
Last Modified: 2013-12-04
Hello.

I have tried to disable the firewall on our networked PCs through the GPO but it doesn't work the rest of the policy kicks in but users are still able to change the firewall settings.  I have tested it through my local GPO and it works.

Any ideas?
0
Comment
Question by:ellisj2006
  • 7
  • 3
  • 2
12 Comments
 
LVL 2

Accepted Solution

by:
morse57 earned 250 total points
ID: 17007963
Hi

Make sure that you don't have a conflicting GPO elsewhere.  If you have set the values in Default Domian Policy, make sure that the key is set as "not defined" in other containers where it appears, such as Client PC or User.

Cheers
Steve

0
 

Author Comment

by:ellisj2006
ID: 17008226
steve,

have checked this out and its not conflicting with any others.  It gives a reason for denial as 'empty' but its not!
0
 
LVL 2

Expert Comment

by:morse57
ID: 17008334
Hi

MS says about "empty" GPO's, "A GPO will be denied if it has no settings. This occurs when an administrator has configured a GPO and linked to it, but has not set any policy settings within the GPO. Either remove the link to the GPO or add policy settings to the GPO. If there are no remaining links to the GPO, you should consider deleting it."

On that basis, it still looks as though a conflicting GPO is winning over the one you want.  Perhaps there has been one previously, which, although It may have been deleted, has left some orphan settings behind.

You could try working through this troubleshooter for GPO's which seem very comprehensive

http://technet2.microsoft.com/WindowsServer/en/Library/6bc554ca-017a-4e30-a0bb-8e87eb646f8c1033.mspx?mfr=true

Hope this helps,
Steve
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17010132
After updating the policy, did you reboot the workstations ? Firewall policy to take effect, the domain computers need to be rebooted.

Cheers,
Rajesh
0
 
LVL 2

Expert Comment

by:morse57
ID: 17010232
They can be, however typing the following in a command window will have exactly the same result:
gpupdate /force

That will requery the GPO's and apply them as they are set.

It is a good idea to do it on the DC first and then the clients.

Cheers
Steve
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17010701
Even if you do the gpupdate /force, you still need a reboot.

Cheers,
Rajesh
0
Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

 
LVL 2

Expert Comment

by:morse57
ID: 17035871
Hi again ellisj2006

Have you got anywhere with this yet?

Kind regards
Steve
0
 

Author Comment

by:ellisj2006
ID: 17036459
sorted thanks Steve
0
 
LVL 2

Expert Comment

by:morse57
ID: 17036782
Was it a conflicting GPO, then? (For the benefit of others viewing the question)

Cheers
Steve
0
 

Author Comment

by:ellisj2006
ID: 17036789
yeah thinkso started a fresh one and it worked fine
0
 
LVL 2

Expert Comment

by:morse57
ID: 17036804
Glad you got it sorted.


0
 
LVL 2

Expert Comment

by:morse57
ID: 17036807
..and thanks for the points

:-)
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Recently, a new law in my state forced us to get a top-to-bottom analysis of all of our contract client's networks. While we have documentation, it was spotty at best for some - and in any event it needed to be checked against reality. That was m…
Our Group Policy work started with Small Business Server in 2000. Microsoft gave us an excellent OU and GPO model in subsequent SBS editions that utilized WMI filters, OU linking, and VBS scripts. These are some of experiences plus our spending a lo…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.
I designed this idea while studying technology in the classroom.  This is a semester long project.  Students are asked to take photographs on a specific topic which they find meaningful, it can be a place or situation such as travel or homelessness.…

914 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now