Re: Troubleshoot remote administration setting in group policy?



Have you same config in both domain and standard profile?

If not, have you verified that domain profile is used and not standard?

--
G Johansson
fantomen@xxxxxxxxxxxxxxx

"Anders" <Anders@xxxxxxxxxxxxxxxxxxxxxxxxx> skrev i meddelandet
news:861EC211-5013-4CAE-A3BD-C83F2A61ACC3@xxxxxxxxxxxxxxxx
As a matter of fact I tried the portqry and this is very peculiar since I
found in some instances that nor group policy or "netsh" command did any
help
http://technet2.microsoft.com/windowsserver/en/library/b8057a7a-a0d3-40b5-8224-ea6a4f5e17231033.mspx?mfr=true

Is it possible for users to configure the firewall to dismiss
policy-settings?


"Darren Mar-Elia" wrote:

You can also use the portqry.exe utility (MS download site) to query the
remote system to make sure you can get through on the ports used by WMI,
like 135 and 445.

Darren

--
Darren Mar-Elia
MS-MVP-Windows Server--Group Policy

Script Group Policy Settings with the GPExpert Scripting Toolkit for
PowerShell!
Find out more at http://www.sdmsoftware.com/products2.php

Visit the GPOGUY: http://www.gpoguy.com -- The Windows Group Policy
Information Hub:
FAQs, Training Videos, Whitepapers and Utilities for all things Group
Policy-related

"G Johansson" <fantomen@xxxxxxxxxxxxxxx> wrote in message
news:eL0GEXZ5HHA.4880@xxxxxxxxxxxxxxxxxxxxxxx
In any case you would need to go to the computer but on the first page
make sure that the firewall settings is using the domain profile and
not
the standard profile (if you have only changed in one of course).
You can always open the firewall and check if your settings has been
applied or not...

Thats my best guesses how to solve it...
--
G Johansson
fantomen@xxxxxxxxxxxxxxx

"Anders" <Anders@xxxxxxxxxxxxxxxxxxxxxxxxx> skrev i meddelandet
news:8BBAE726-A8B9-4E1B-8718-462B9A9F2D84@xxxxxxxxxxxxxxxx
Hello, I have an inventory WMI scanning program and in order to enable
scanning of clients with enabled firewalls I have set the domain level
policy
to allow remote administration in the group policy for Windows
firewall.
However, I have noticed that the scanning cannot detect certain
computers
with the firewall enabled so how can I troubleshoot that this firewall
exception policy has indeed propagated to the client?






.



Relevant Pages

  • Re: Group Policy
    ... Assuming the client computers are XP Pro edit or create a Group Policy and ... your domain network and standard profile is applied when the computer is off ... the domain network such as a roaming laptop. ... Firewall: protect all network connections to disable the Windows Firewall. ...
    (microsoft.public.win2000.security)
  • Re: Group Policy not applied after reboot (intermittent)
    ... It shows the Standard Profile for the firewall is ... applied instead of the Domain Profile, even though the GPO was successfully ...
    (microsoft.public.windows.group_policy)
  • XP SP2 & GPO controlled firewall gets activated for unknown reasons...
    ... I configured GroupPolicy to control the XP SP2 Firewall using the ... In the standard profile, the firewall ... in the Domain profile, the firewall is off. ...
    (Focus-Microsoft)
  • Re: XP machine removed from domain still gets domain policy
    ... then turn off the firewall. ... Prohibit use of the Internet Connection Firewall on your DNS domain network? ... Firewall settings), the Firewall settings revert back to the default and ... the only Group Policy being applied is the "Local Group Policy" ...
    (microsoft.public.windows.group_policy)
  • Re: Network Services/NT Authority
    ... OK that is what I though in that you did not change any Group Policy ... settings but instead were managing the Windows Firewall settings and no you ... logon which is normal as your computer really is on a network - the ... ICMP and then the option to reset all the firewall ...
    (microsoft.public.windowsxp.security_admin)