Disable firewall on domain computers with Policy - problem

Ron Dokken
Ron Dokken used Ask the Experts™
on
I want to disable firewall on all computers attached to the domain as in the picture below.
The dc runs on Win 2012 Server (std, not r2)

Problem:
When editing GPO "Default Domain Policy", the values can't be changed in gpmc. E.g. they don't "stick".

Then I created a new gpo, MYGPO, linked it to the domain, and edited the settings. This time the settings "stuck".
But the firewall settings does not end up on domain computers, even after restart.

I could see in a log file that MYGPO was applied to the domain computer (correct linking I assume).

What went wrong and what to do about it?

gpmc edit fw
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Senior Solution Architect
Most Valuable Expert 2015
Top Expert 2015
Commented:
Based on what you have provided in your screenshot the issue is that you have "Not Configured" anything for windows firewall. Leaving the policy as NOT CONFIGURED means it is not going to do anything on the users machines. You need to set this to Off for Firewall State. Then try again.

If it still does not work then you might have a policy processing issue, i.e. security filtering.

I have just tested this in my lab and it works without and issue. Just run gpupdate /force and it will automatically change the value. You should not have to reboot it.

Will.

Author

Commented:
Can't change the value in default domain policy..

Author

Commented:
Found this in the System log on DC..

"The processing of Group Policy failed because of an internal system error. Please see the Group Policy operational log for the specific error message. An attempt will be made to process Group Policy again at the next refresh cycle."

Where is the Group Policy operational log?
Ensure you’re charging the right price for your IT

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Author

Commented:
Does it matter that windows is not yet activated? It's dev VM.

Author

Commented:
gpresult /h report.html yielded this..

ee.png

Author

Commented:
gpupdate /force revealed that GPO "Default Domain Policy" was corrupt.. Probably because of previous scripting activities.. Note to self, don't script policies. Edit in gpmc.msc and then backup-gpo / import-gpo :)

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial