Re: Domain Controller Firewall

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



I certainly do not mind Cary. I believe multiple opinions are more
beneficial to the OP than one.

> In another thread (do not remember where it is....either in this one or in
> the Group Policy newsgroup) it has been suggested that running the
> software Firewall on a Domain Controller is not needed and was recommended
> to not implement.

Haven't read that myself, but I'm about 18 months behind on my reading, so
it doesn't surprise me. Personally, I don't enable the firewall on any
servers. I like the feature of SP1 that enables by default until we run
Windows update and then disables. But after that, none of our client's
servers have this enabled. Client PCs certainly. But the servers don't
move around into and out of secure areas, and are well protected by the
hordes of perimeter firewalls and other security devices in and around the
VLANs in the data centres.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net


.



Relevant Pages

  • Re: Windows Updates: Firewall setting for outbound traffic
    ... The trusted zone for Windows Update should be a separate one in your ... Only have one trusted sites zone, and include only the following 3 ... Make sure your firewall allows, at least to the zones above, Win32 ... > outbound traffic from the servers to the internet. ...
    (microsoft.public.windowsupdate)
  • Re: Domain Controller Firewall
    ... I am about three years behind in my reading! ... I don't enable the firewall on any ... I like the feature of SP1 that enables by default until we run ... > servers have this enabled. ...
    (microsoft.public.windows.server.active_directory)
  • Windows Update addresses?
    ... firewall and all computers must use our proxy server. ... It seems that windows update will only use the proxy settings if they ... servers, but I need a list of addresses of these servers... ...
    (microsoft.public.windowsxp.help_and_support)
  • Windows Update Site Stopped Working
    ... Until last week I used Windows Update Service on my ... Windows 2000 Servers to get the latest security patches. ... I get a HEX error code ... new site regarding firewall rules. ...
    (microsoft.public.win2000.security)
  • Re: Windows update and firewall
    ... > the IP address of the servers so that it can get past the firewall. ... > Does anyone have a list of the windows update servers IP address's? ... -- torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway Administration scripting examples and an ONLINE version of the 1328 page Scripting Guide: ...
    (microsoft.public.windowsupdate)