SBS
--
Questions
--
Followers
Top Experts
I'm having some troubles with the console on SBS 2008. Every XP client on the network is shown with the firewall OFF. When I check the firewall on the clients security center or with "netsh firewall show state" it's ON and working as it should.
What should I try in order to get this fixed?
Thanks a lot.
Alex.
Zero AI Policy
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
Do they have any third party firewall software installed on them? If so, then check with the product's manufacturer to see if they have properly validated the product you are using for SBS 2008.
Philip
MPECS Inc.
Thanks again for your help.
Philip






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Yes, all the boxes are up to date with all updates installed, even Group Policy Preference Client Side Extensions for Windows XP (KB943729).
Do you have:
http://support.microsoft.com/KB/958715
SBS 2008 Rollup 1.
Please make sure your server is backed up prior to running this update.
Philip
Â

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
Anything I should try next Philip? Thanks a lot.
Alex.
Create and link a GPO and call it TestGPO.
 Edit the new GPO and "Not Configured" the domain based firewall settings.
 Close the GPO editor.
 Right click on the new GPO and set to Enforced.
 Move one workstation into the new OU via ADUC.
 GPUpdate /force on both SBS (first) and then the workstation.
Manually disable the firewall settings.
GPUpdate /force on the workstation. It probably will not hit the console yet.
Manually enable the firewall settings.
GPUpdate /force
Reboot the workstation.
Wait until the console picks it up.
See what happens. Perhaps there is a hook missing in there somewhere and this may reset it.
Did you use the http://connect wizard to add the systems to the SBS domain?
Philip
MPECS Inc.
On any of your deployments did you ever saw a client firewall reported on? I mean not with unknown status but on in the SBS 2008 security console? Being reported with unknown status will get you a green check mark so you really need to look into the details to find this out. Thanks again for your great help.
Alex.






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
We pushed a domain account to all of the workstations via GP Preferences and set it in the local admin group on the machines. All default local admin accounts are disabled via GP Preference too. We rotate the password on that account as soon as the user that needed it is done.
No one can install or make changes on the domain without that password since they are all running as Standard Users.
All firewalls are Windows native and managed by GP. The Domain Security Center is also enabled via GP.
Philip

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
Philip
MPECS Inc.
I did more research on this with my test deployment and I find out that if I deploy OneCare on my clients it automatically enables its firewall module and disable the native windows one. When this happens SBS reports the clients finally with firewall on. If I turn OneCare firewall off and I turn on again the windows one, SBS tells me that the firewall status is off. It seems that it's really a problem with SBS that cannot see the status of the native firewall of Vista and XP as enabled. Maybe you can confirm this also?
Thanks,
Alex.
I think I figured it out. Native windows firewall doesn't have an instance registered with WMI. You can check this both on Vista and XP using wbemtest--->SecurityCenter
So to get back now to my initial problem. Trend WFBSA is registering an instance of the firewall on XP and turns it off so this is how SBS gets confused and reports that XPs have the firewall off. At least I think this is the case. I will do more testing tomorrow and let you know.
I'm tired and it's late. I hope what I'm saying makes sense to you also Philip.






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Thanks again for your help Philip. I consider all your guidance very helpful and will accept as a solution one of your answers.
Best regards,
Alex.
Philip
SBS
--
Questions
--
Followers
Top Experts
Small Business Server (SBS) is a line of server operating systems targeted at small businesses by bundling the operating system with a number of other Microsoft products that would normally need to be purchased or licensed separately. The most notable inclusions are Exchange, SQL Server, SharePoint and ISA/TMG (Microsoft's firewall and proxy server).