Re: firewall
- From: "Jon Straub" <jstraub@xxxxxxxxxxxxx>
- Date: Wed, 22 Feb 2006 09:09:18 -0800
thank you
I was able to disable server control over my workstations firewall.
when my network is larger I'll consider using that policy
thanks
jon
"Steve Foster [SBS MVP]" <steve.foster@xxxxxxxxxxxxx> wrote in message
news:xn0eiscyj000007y@xxxxxxxxxxxxxxxxxxxxxxx
news.microsoft.com wrote:
when I upgraded to sp1 of sbs the firewall setting on my xp pro
workstations became controlled by server. but the server firewall is not
installed because I don't have two nic cards. how do I give the control
back to the workstations.
The presence or not of a firewall on the SBS is irrelevant to managing the
clients' Windows Firewall.
Configuration of the desktop Windows Firewall is managed via Group Policy.
Look under Administrative Tools > Group Policy Management, or under
Advanced Management > Group Policy Management in the SBS Server Management
console, and drill down to the "SBS Windows Firewall" policy. Edit this to
manipulate the Windows Firewall for all client machines.
I'd strongly recommend leaving it on - it's a secondary line of defence
against an infected workstation spewing crap all over your network.
Adding exceptions for specific applications ("Program Exceptions") via the
GPO "SBS Windows Firewall" is pretty easy. Here are some example entries
(watch out for line wrap):
Sophos AV:
%ProgramFiles%\Sophos\Remote Management
System\RouterNT.EXE:LocalSubnet:Enabled:Sophos Remote Management
Grisoft AVG:
%Windir%\AVGAgent.EXE:LocalSubnet:Enabled:Grisoft AVG Agent
%ProgramFiles%\Grisoft\AVG7\AVGCC.EXE:LocalSubnet:Enabled:Grisoft AVG
Control Centre
VNC:
%ProgramFiles%\ORL\VNC\WinVNC.exe:LocalSubnet:Enabled:VNC
Add the exceptions before installing the relevant application, and
remember to allow time for the updated GPO to be picked up by the clients,
or manually force individual machines with "GPUPDATE /force" from a
command prompt.
--
Steve Foster [SBS MVP]
---------------------------------------
MVPs do not work for Microsoft. Please reply only to the newsgroups.
.
- References:
- firewall
- From: news.microsoft.com
- Re: firewall
- From: Steve Foster [SBS MVP]
- firewall
- Prev by Date: Re: DHCP Issues. Very strange
- Next by Date: Fax routing
- Previous by thread: Re: firewall
- Next by thread: Unable to connect to \\127.0.0.1
- Index(es):
Relevant Pages
|
Loading