Re: Group Policy Delegation

Tech-Archive recommends: Speed Up your PC by fixing your registry



"Please let me know the detail purpose of your action."

I trying to I am trying to control the local windows firewall on the
workstations. Enabling certain ports to be opened and specific
programs to be disabled.


I double checked my settings and tried a different approach. I added
the computer name to the deligation list then added the Apply Group
Policy check for it alone.

It worked!

I tried once more to apply the policy to Authenticated users and
brought down the entire corporation. (oops)

After removing the policy and enabling the company to work, I checked
the Domain controller firewall. It is dissabled, because a alternate
firewall is being used by the server. I enabled it for a second and
found the same problem as in having the policy enabled, So I added the
server to the list and denied the right to Apply Group Policy for the
Firewall GPo. When I enabled the policy for Authenticated users it
worked properly.

I guess my question is this...

Is it considered "Standard Policy" to remove the Domain Servers and/or
Administrative accounts from All policies in general or policies like a
firewall policy?

.



Relevant Pages

  • Re: [fw-wiz] httport 3snf
    ... > Having worked in the Firewall support role at several companies, ... I had my CIO approve my security policy. ... time educating him about Internet risk. ... There's also a very good "at what point is the firewall now useless" ...
    (Firewall-Wizards)
  • RE: Sandboxing
    ... the 3Com Embedded Firewall would be extremely useful and enabling (in ... your case) when you look at it in a VPN context. ... This security policy will accomplish quite a few things: ... During the Policy Server installation, ...
    (Focus-IDS)
  • Re: Questions About Windows Firewall and Domain Policy Enforcement
    ... Can you please provide me with more detail with what you mean by connecting ... configure the firewall, namely group policy, net shell scripts, manual ... You can do this through group policy or a login script. ... > as there is no Standard Profile configured. ...
    (microsoft.public.win2000.group_policy)
  • Re: Questions About Windows Firewall and Domain Policy Enforcement
    ... Can you please provide me with more detail with what you mean by connecting ... configure the firewall, namely group policy, net shell scripts, manual ... You can do this through group policy or a login script. ... > as there is no Standard Profile configured. ...
    (microsoft.public.windows.group_policy)
  • RE: Ensuring Disabling/Uninstalation of Windows XP Firewall in LA N enviro.
    ... Since the Group Policy editor is really just a fancy GUI for making registry ... Ensuring Disabling/Uninstalation of Windows XP Firewall in LAN ... Since this is not an AD environment as yet, ...
    (Focus-Microsoft)