Solved

Trying to enable Domain firewall

Posted on 2012-03-10
7
393 Views
Last Modified: 2012-08-13
I just migrated my client from Server 2003 Enterprise to SBS 2011. I have found that every single workstation has the firewall disabled. The Domain firewall option is greyed out on the workstation saying that this setting is managed by your system administrator.

I went to the server and Opened Group Policy.
I navigated to "Domains - Company.local - MyBusiness - Computers - SBSComputers - Windows SBS Client Computers Windows 7" and edited the GPO There.

The exact GPO I enabled is "Computer Configuration - Policies - Administrative Templates - Network - Network Connections - Domain Profile - Windows Firewall: Protect all Network Connections"

I ensured that the link was both enabled and enforced but the workstation firewalls remain off.
How do I enable the Domain firewall?
0
Comment
Question by:LostInWindows
  • 4
  • 3
7 Comments
 
LVL 5

Expert Comment

by:BAYCCS
ID: 37705147
Run a group policy result against one for the workstations from group policy management on the sbs server. Review the settings after the report is made. The settings may be coming from another GP.
0
 
LVL 1

Author Comment

by:LostInWindows
ID: 37705249
I ran the GP Result from 1 workstation and it says:
Firewall State       Off            Default Domain Policy
How do I enable it?
0
 
LVL 5

Accepted Solution

by:
BAYCCS earned 500 total points
ID: 37705269
Repeat the steps that you did above but this time edit the gpo named "Default Domain Policy". If you open group policy management the default policy is usually listed towards the top, or there should be a folder called group policy objects which will display all the gpos in your organization.
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 1

Author Comment

by:LostInWindows
ID: 37705272
That GPO was listed as Disabled. I enabled it.  I will wait an hour and see if that changes my result.
Thanks!
0
 
LVL 5

Expert Comment

by:BAYCCS
ID: 37705281
The only question that you might want to ask yourself is, why was it disabled? Someone disabled that GPO for a reason.

I just don't want another issue to come up and bite you....
0
 
LVL 1

Author Comment

by:LostInWindows
ID: 37705283
I need to look at the GPO on the old server.
I have looked after this company for more than 6 months and there is no reason for it to be disabled.
0
 
LVL 1

Author Closing Comment

by:LostInWindows
ID: 37705460
Thank you,
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now