Re: Server 2008 with Hyper-V - domain controller - Firewall GUI's show firewall ON, but netsh reports firewall OFF





"Bruce Sanderson" <bsanders@xxxxxxxxxxxxx> wrote in message news:O44qIZgFJHA.4064@xxxxxxxxxxxxxxxxxxxxxxx
Bill, thanks for your reply.

This physical computer has only one network adapter and there are virtual machines that (when they are running) communicate with each other, other LAN attached computers and the Internet (via a router), so yes, there is a virtual network linked to the NIC.

I ran the netsh advfirewall show currentprofile on another Windows Server 2008 Domain Controller (single DC in experimental domain) installation and it shows:

Domain Profile Settings
--------------------------------------------
State ON

So, looks like you're supposition that Hyper-V is causing the discrepancy is most likely bang on.

In a "production" installation, I wouldn't recomend using the Hyper-V parent partition as a Domain Controller either. In my simple home installation, the server is mostly to be a domain controller and WSUS server - running Virtual Machines is secondary, but I wanted to get some experience with Hyper-V, so added that role.

I find many references in forums, articles etc. that say "Microsoft recommends" not running applications in the Parent vm, but I can't find any Microsoft document that says this (not that it/they don't exist, just I can't find them!). Do you know where such recommendations by Microsoft can be found? I'd like to have it handy for future reference.

--
Bruce Sanderson
http://members.shaw.ca/bsanders

It is perfectly useless to know the right answer to the wrong question.


Here is a link to a Technet article which mentions it.

http://technet.microsoft.com/en-us/library/cc794726.aspx

The main reasons seem to be security based, not performance based.

.



Relevant Pages

  • Re: "broken"/missing ACLs?
    ... explains many of the settings that can cause a problem. ... >the domain controller consistently. ... >for the network adapter, bad CAT5 cable, or even a problem with the switch ... >> icon and the ACL name itself is a long string of alphanums. ...
    (microsoft.public.windowsxp.security_admin)
  • Multi homed DC
    ... we had to add a second network adapter to ... This commands is run from another domain controller. ... Master browser name is: SDR100A ...
    (microsoft.public.windows.server.active_directory)
  • RE: ping dor doomain name not correct
    ... How DNS Support for Active Directory Works ... virtual network adapter) was installed in domain controller, ... Microsoft Online Support ...
    (microsoft.public.windows.server.networking)
  • Remove Domain Controller
    ... Cannot remove Domain Controller in active directory users ... The physical computer is off the network. ... When trying to delete get an error message "The DSA object ...
    (microsoft.public.windows.server.general)
  • Why do I have to leave & rejoin the domain to make logins work?
    ... domain controller is down or otherwise unavailable, ... To fix the problem I have to leave and rejoin the domain. ... Windows XP Pro SP3 on the virtual machines. ...
    (microsoft.public.windows.server.general)