Re: Windows 2003 SP1 Firewall Control through Group Policy



Roger Abell [MVP] wrote:
You are really asking group policy questions, but not in
microsoft.public.windows.group_policy
which would be the best place.

What you ask in your follow-up post is a standard practice
in group policy of applying a GPO to a selected set of targets.
You may accomplish this by OU linkage of GPO or security
group filtering.

MS has extensive writeups on the firewall settings, if you were
to search the ms.com website.
One thing I might add is that you should carefully consider how
you use the domain vs standalone policies as the domain policy
tends to not be used by a domain member if there is any issue
with the network interface being unavailable during application.

Roger
"stosti" <stosti@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:4AFC15A0-5080-438C-A301-FF62439D61C3@xxxxxxxxxxxxxxxx
Thank You!

Is there a way to turn on the firewall on some machines and not others?
Currently my remote users have the firewall enabled. My internal users
have
it disabled. I want to setup the GP to keep this the same. External
users
must have the firewall and internal users need it disabled...

Regards,
Scott

"Jerold Schulman" wrote:

On Sun, 15 Oct 2006 04:59:01 -0700, stosti
<stosti@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:

Hi,

How do I control the firewalls on my XP client machines through GP? Can
I
exclude my 2003 servers? Can I exclude the firewalls on some XP
clients?
Can I set configure which ports I want open though GP? I need SMS,
Symantec,
Remote Desktop and alike to be able to function with the firewalls
enabled.

Thank You,
Scott
See the following in the 'Tips & Tricks' at http://www.jsifaq.com
JSI Tip 8378. Windows XP SP2 Firewall Update for Windows Small Business
Server 2003.

JSI Tip 10218. How to Troubleshoot Windows Firewall settings in Windows
XP Service Pack 2?

JSI Tip 8447. You cannot configure Windows Firewall settings, or Security
Center settings, on Windows XP Service Pack 2 in a SBS 2003 domain?

JSI Tip 7907. How do I open port 445 for remote administration of Windows
XP (SP2 or greater) with the Windows Firewall enabled?

JSI Tip 8866. GPMC in Windows XP SP2 displays some Group Policy settings
in Extra Registry Settings?

JSI Tip 9254. How might you configure the Windows Firewall using the
Group Policy Management Console on your Windows Server 2003 SP1 computer?

JSI Tip 8203. The SMS Administrator console cannot display Event Viewer,
Windows Diagnostics, or Performance Monitor for Windows XP Service Pack 2
clients?

JSI Tip 8382. Managing Windows XP Service Pack 2 Features Using Group
Policy White Paper.



Jerold Schulman
Windows Server MVP
JSI, Inc.
http://www.jsiinc.com
http://www.jsifaq.com




Roger,

Just FYI, I personally use the Standard and Domain firewall profiles in
my environment and haven't had any issues. It is good to be aware that
networking issues at boot-up could affect the application of this GPO,
however it has been in my experience that as long as users are aware of
the plugin-before-bootup concept, they've been fine.

Trevor Sullivan
MCP
.



Relevant Pages

  • Re: How do I turn off SP2 firewal Group Policy setting
    ... I followed the instructions, but when I go to modify Group Policy, all ... settings are Not Configured Already. ... > Windows XP SP2 client computer in the SBS domain. ... > Firewall for client computers that are running Windows XP Professional. ...
    (microsoft.public.windows.server.sbs)
  • Re: Windows 2003 SP1 Firewall Control through Group Policy
    ... MS has extensive writeups on the firewall settings, ... Currently my remote users have the firewall enabled. ... JSI Tip 8378. ... Windows XP SP2 Firewall Update for Windows Small Business ...
    (microsoft.public.windows.server.active_directory)
  • RE: SBS 2003 & Win2K DC
    ... 872769 You cannot configure Windows Firewall settings or Security Center ... | why a change I made to Group Policy (using gpupdate /force after the ...
    (microsoft.public.windows.server.sbs)
  • RE: Workstation Firewall / Group Policy
    ... configure the clients' firewall by SBS GPO to let network backup software ... you could try to edit the GPO '' Small Business Server Windows ... Firewall'' on SBS to configure the firewall on client. ... been truncated" error message when you edit or view Group Policy in Windows ...
    (microsoft.public.windows.server.sbs)
  • Re: GPO does not disable XP Firewall
    ... I'm assuming your talking about the Windows Firewall/Internet Connection ... > network connections: Disabled ... > use of Firewall on Internet Domain: ... > Last time Group Policy was app ...
    (microsoft.public.windows.group_policy)