Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Need windows firewall disabled/grayed out when on SBS 2003 network but need user to be able to turn windows firewall on/off when off the network to use VPN

Posted on 2006-06-29
6
Medium Priority
?
796 Views
Last Modified: 2008-03-26
Currently I have the GP on the SBS 2003 server disabled for the network profile and not configured for the standard profile.  This keeps the firewall off while they are on the network (which I want) but when they are off the network the windows firewall is on and grayed out and says set by group policy).  I have some users that need the windows firewall to be on when they are not on the network and some that need to be able to turn it off when they are off the network so they can use their VPN client.  How do I configure the GP to allow them the ability to turn it on and off when they are not on the network?
0
Comment
Question by:studios
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
6 Comments
 
LVL 3

Expert Comment

by:EE33
ID: 17015271
You could disable the firewall by going into Services and turning the service off but there
is a problem - the Windows Firewall is tied in with "Internet Connection Sharing"

On a network I should think you need the Internet Connection Sharing (ICS) service
always running to even communicate with the other systems. But like you say, you
would be on a Virtual Private Network so I am not too sure if you would need ICS
but more than likely you will. Blame Microsoft, I do! Why they tied the two services
together like that is beyond me its just stupid and a bad design.
0
 
LVL 3

Expert Comment

by:EE33
ID: 17015285
Sorry you said...

"How do I configure the GP to allow them the ability to turn it on and off when they are not on the network?"

When they are not on the network OK...

These users can't disable and enable services if they are just "Users"

See if this helps, it sems to deal with your needs....

http://www.jsifaq.com/subj/tip4600/rh4673.htm
0
 
LVL 3

Expert Comment

by:EE33
ID: 17015324
That article does not mention that you first have to ceate
the snap in to access "Active Directory Users and Computers"

Start > Run > 

Type: MMC

Then: File > Add/Remove Snap-In > Add > Active Directory Users and Computers

Then you'd have to follow the guide from the link above.
0
 
LVL 24

Accepted Solution

by:
Kenneniah earned 500 total points
ID: 17019106
When setting the Firewall to on or off using group policy, no, there is no way to give users the ability to change it. That's the whole point of setting it with group policy.

However, you should be able to get a VPN client to work fine with the firewall enabled. Just set up exceptions in your GPOs Standard Profile firewall settings. For some VPN connections, just enabling "Allow incoming echo request" and "Allow outgoing destination unreachable" in "Windows Firewall: Allow ICMP Exceptions".
Depending on what VPN client etc, you may have to set up Port exceptions, program exceptions etc.
0

Featured Post

Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Can I legally transfer my OEM version of Windows to another PC?  (AKA - Can I put a new systemboard in my OEM PC?) Few of us are both IT and legal experts but we all have our own views of Microsoft's licensing rules and how they apply.  There are…
Sometimes people don't understand why download speed shows differently for Windows than Linux.Specially, this article covers and shows the solution for throughput difference for Windows than a Linux machine. For this, I arranged a test scenario.I…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
How to fix incompatible JVM issue while installing Eclipse While installing Eclipse in windows, got one error like above and unable to proceed with the installation. This video describes how to successfully install Eclipse. How to solve incompa…

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question