create a GPO to allow an inbount rule

Hi,

I need to create a GPO to add an inbound rule of a Windows 7 firewall to allow a specific TCP port.

Our DC is running Windows 2008.

Please advise how to do that.

Thanks.
nav2567Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

becraigCommented:
Here is a very clear step by step
http://www.grouppolicy.biz/2010/07/how-to-manage-windows-firewall-settings-using-group-policy/

Basically you just need to load firewall control panel
Create the policy
Export the policy
Then load the group policy manager, navigate to firewall rules/ inbound
Import the policy
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
McKnifeCommented:
But would he want to import the whole policy (=all rules of the computer you export from)? I'd simply add this one rule.
0
nav2567Author Commented:
I need to ADD a policy for the PC to allow a specify incoming port, and also MODIFY a few existing incoming policies and add an IP address to their scope.  

I am see double entries on the MODIFIED incoming policies.  Please see attached.
fw.png
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

McKnifeCommented:
As far as I know, you can use GPOs only to add rules, not to modify existing ones.
You would need to resort to startup scripts that make use of the command netsh.exe /firewall  to make granular changes to existing ones.
0
nav2567Author Commented:
I forgot to say, besides the double entries, I also do not see the rule I added before I exported.
0
becraigCommented:
Adding to what MCKnife is indicating my steps are an expectation that you have a computer that will drive firewall policy where configs are made and then imported  for that GPO.

If you have a server by server need then you will have to use netsh. e.g
netsh advfirewall firewall add rule name=FWRule_Name dir=in protocol=tcp localport=xxx-xxxx action=allow

Open in new window

0
nav2567Author Commented:
These were what I did:
. create a new rule in Inbound Rules
. After finish, click "Windows Firewall with Advanced Security on Local Computer"
. Action
. export policy
. copy saved policy to a domain controller
. open up gpmc
. create a new GPO
. edit gpo and edit computer configuration>policies>windows settings>security settings>windows firewall with advance security
. import the policy.

Please let me know I miss anything.

Thanks.
0
McKnifeCommented:
Again let's look at what leads to those doubles you see: the policies you set via GPO will not overwrite the present ones. They will co-exist. That's why we recommend netsh-scripting.
0
nav2567Author Commented:
Ok, fine.

Any idea of why the new rule was not added?
0
McKnifeCommented:
Are you sure that is wasn't? Because what your picture shows are not the same rules - they differ in the rightmost column.
0
becraigCommented:
There should be no reason why the defined rule did not show up.

You can go ahead and add it using netsh and check again.

Can you give any details on the rule you are trying to add
0
nav2567Author Commented:
I see the added rule now.  

I am going to export one more time without customize existing rules and see if there is any duplicates.

Thanks.
0
becraigCommented:
Great, in the future you can use the format from the netsh command I have above 40465686 as an additional option if you do not have a computer from which you can create and fine tune firewall policies for your environment,

Netsh is quite robust and you can configure every aspect of a new firewall rule using this.
0
nav2567Author Commented:
thanks a lot, guys.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.