Solved

Enable iSCSI service on Windows firewall through Group Policy

Posted on 2012-03-15
7
785 Views
Last Modified: 2012-04-02
Are setup: Windows 7 32bit OS, Server 2008R2

I want to enable iSCSI service tcp-in for all networks on the firewall. I would like to do this through Group Policy. I have tried adding this already and created a rule but it will not apply. I have tested just turning the firewall off and it works fine, but I would prefer not to do that for just one thing. I know I do this in Computer Config\Policies\Windows Settings\Security Settings and then Firewall. When I applied and checked with gpresult /r on the PC I am testing on it says "denied access".

Any assistance is appreciated. Let me know if you have any questions.

Thank you,
0
Comment
Question by:SilverSharp
  • 4
  • 2
7 Comments
 
LVL 78

Expert Comment

by:arnold
ID: 37726924
Not sure what the point is since the only iscsi target host is the windows 2008 server, what port are you allowing and what is the security filter you are using for the GPO?

Are you allowing port 3250 for the discovery?
Use gpmc to get info policy events to see why it is being denied.
0
 

Author Comment

by:SilverSharp
ID: 37729705
Yea, we are using the iSCSI service to do discovery. We have an application that will detect what user is on a specific computer. Do you mean allowing port 3260? Do I need to run the gpmc from the PC I am trying to apply it to?
0
 
LVL 78

Expert Comment

by:arnold
ID: 37729843
You would run GPMC on the DC and then use the group policy results wizard to see what policy applies to a computer/user and there you should see why a setting is not being applied i.e. there is another policy that is processed first and is the one the sets the item, i.e. causing a conflict. you could enforce the policy to make sure it takes precedent over all others.
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 40

Expert Comment

by:footech
ID: 37734124
You're probably getting a "denied access" because of security filtering.  If you could provide what settings you are using for this on your GPO as Arnold asked, it would be helpful.

If you're not too familiar with group policy, computer settings have to apply to computer objects in AD.  You should link the GPO to an OU (or it's parent OU) that has the computer objects you want to apply to (if you have set up an OU for this purpose), or you can link at the domain level (if all your computers are in the default computers container).  If you have security filtering set to "Authenticated Users" it will match both users and computers.  If you think this sounds like a problem, that's not necessarily true.  If your GPO only has computer settings, it won't apply to users and vice versa.
0
 

Author Comment

by:SilverSharp
ID: 37737596
So would it be best to create an OU - maybe called Firewall, add all the OU's I created for each dept - add them in and then put that in the GP?
0
 
LVL 78

Accepted Solution

by:
arnold earned 255 total points
ID: 37737641
What is the result of running gpmc on one computer? Do you have another policy that deals with firewall settings?
The GPO applies based on group memberships, so you would either need to apply this policy at the top of the ad, or added/linked to each OU.
0
 
LVL 78

Expert Comment

by:arnold
ID: 37737646
There are other methods to have users setup with a GPO login script that will reord the user that logged into a system.  The script can add the data to a flat file or into a database depending on your needs.
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

You may have a outside contractor who comes in once a week or seasonal to do some work in your office but you only want to give him access to the programs and files he needs and keep privet all other documents and programs, can you do this on a loca…
When you try to extract and to view the contents of a Microsoft Update Standalone Package (MSU) for Windows Vista, you cannot extract the files from the MSU. Here we are going to explain how to extract those hotfix details without using any third pa…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum editing capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.

713 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question