Solved

Where in Group Policy are the Firewall settings for work stations?

Posted on 2015-01-21
7
255 Views
Last Modified: 2015-01-27
We have a Windows 2008 R2 Server. All workstations are Windows 7 Pro.

The Windows Firewall for all the workstations is showing off.  If we try to turn it on, we get the message:

Windows Firewall can't change some of your settings because they are controlled by Group Policy. Contact your system administrator if you need to change the settings.

So I am looking at the Group Policy settings and trying to find where I can turn the firewall on ONLY for the workstations.

Can someone advise exactly where that setting is.
We want the workstations to have the MS Firewall turned on... but when we try
0
Comment
Question by:Tomster2
7 Comments
 
LVL 21

Assisted Solution

by:Joseph Moody
Joseph Moody earned 75 total points
Comment Utility
These settings are in a few places. The easiest way for you to see where is to run a GPResult from the client. You can run GPResult /h report.htm to generate a report.

Here is a guide if you need it: http://deployhappiness.com/gpresult-or-rsop/
0
 
LVL 32

Accepted Solution

by:
it_saige earned 350 total points
Comment Utility
In Computer Configuration -> Policies -> Windows Settings -> Security Settings -> Windows Firewall with Advanced Security.Capture.JPGIn the future, you can run the Resultant Set of Policy in 'Logging mode' in order to find where your policies are defined.

To run the Resultant Set of Policy (RSoP).
1.  Open MMC.
2.  Choos File -> Add/Remove Snap-in.
3.  Find and add the Resultant Set of Policy snap-in the the 'Selected snap-ins' list.  Press OK.
4.  Right-click on the Resultant Set of Policy and Choose 'Generate RSoP'.
5.  Follow the steps in the wizard to choose the options.

-saige-
0
 
LVL 3

Assisted Solution

by:Bahloul
Bahloul earned 75 total points
Comment Utility
Hi,

view the below link it will provide you all configurations:-

https://technet.microsoft.com/en-us/library/bb490626.aspx

Bahloul.
0
Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

 

Author Comment

by:Tomster2
Comment Utility
Sorry for the delay... will be working on this Tuesday (tomorrow).  Thanks for the replies will respond back when I try the info out.
0
 

Author Comment

by:Tomster2
Comment Utility
I went to the screen saige suggested... I then configured the domain network to be on, using default settings for both inbound and outbound.

That turned the workstation firewalls on... and also the server... stopping all communication to the server We use a server install of Quickbooks - and all of the workstations loss access.

I went back to the server, same location, and changed the inbound, outbound and server settings to "not configured" ... but that left the firewalls for the server and the workstations on... and they remained on after a reboot.  Going to Turn Windows firewall on or off (server or workstations) gives the message: "For your security, some settings are managed by your system administrator." Fine... but I just put them back to unconfigured. Why are they still on...

As a stop gap, I tried turning the Windows Firewall Service on the Server off... but the workstations still cannot access the server. Everything is at a standstill.

Help!
0
 
LVL 32

Assisted Solution

by:it_saige
it_saige earned 350 total points
Comment Utility
After you changed the settings to Not Configured, did you run a gpupdate /force in order to immediately put those settings into affect?

Also, to immediately restore connectivity, you can change the settings (on the server) in the registry.  Navigate to -
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\

Open in new window

You will see multiple keys:
DomainProfile
FirewallRules
PublicProfile
RestrictedService
StandardProfile

Of these DomainProfile, PublicProfile and StandardProfile affect the enabling and disabling of the firewall.
To disable the firewall, select the key; i.e. DomainProfile and change the value of EnableFirewall to 0.

-saige-
0
 

Author Comment

by:Tomster2
Comment Utility
Thank saige. While I was panicing I ran across a thread on the gpupdate /force.  I had forgotten about the delay time as I had not worked with gp for quite a while.

So now there was finally a correlation between what I was doing on the server.... with the results on the workstation.  I then got connectivity restored.

Will be working a bit more with this.

Thanks to everyone for the posts. Will be splitting the points.
0

Featured Post

Why do Marketing keep bothering you?

Is your marketing department constantly asking for new email signature updates? Are they requesting a different design for every department? Do they need yet another banner added? Don’t let it get you down! There is an easy way to manage all of these requests...

Join & Write a Comment

This article covers how to install the Microsoft Windows Operating System (OS). What is covered in this article:  > Different Versions and Editions of the Windows OS  > Upgrading versus Fresh Installation of the OS           - Steps to take pr…
Preface There are many applications where some computing systems need have their system clocks running synchronized within a small margin and eventually need to be in sync with the global time. There are different solutions for this, i.e. the W3…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now