Re: Firewall



hood <hood4u@xxxxxxxxx> wrote:
On Mar 20, 12:58 pm, "Lanwench [MVP - Exchange]"
<lanwe...@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
hood <hoo...@xxxxxxxxx> wrote:
I have over 30 computers that have no problem whatsoever with the
windows firewall. A newly bought Dell is giving me problems.

What's different about it?

When I
log onto the workstation as the local administrator I can shut off
the firewall, as we don't need it. If I log onto the network as the
user that will be using the computer I don't have rights to change
the firewall settings, which is fine that is what I want. On all
the other workstations I can log in as local admin and shut off the
firewall and when the users log onto the network from those
workstations the setting stays; the firewall is off. When I log
onto the local admin of the new Dell computer I can turn off the
firewall and the setting stays. But, when I log in as the user the
firewall is on and i am having problems running other programs. Is
there a way that I can log in as the user and then use one of my
admin passwords to change the settings??

Back up a bit - if you want to manage your windows firewall on al
the workstations, you really should use group policy to do it. Don't
manually set up stuff like this piecemeal on workstations - you're
defeating some of the main benefits of having a domain in the first
place, which is centralized management and control.

And veering a bit off topic, I strongly recommend you leave it
running & enabled, and set exceptions for it. It's a valuable
security barrier even if you also have a perimeter firewall. You
will find this out if you ever get into the situation of malware,
etc., running amok on your network.

That all said, run rsop.msc as the user on this workstation to find
out what the effective policies are, and also check the event logs.

I don't know if it is a firewall setting but i am also disallowed,
while logged in as the user of the workstation, from creating files
or changing them/saving them. I cannot save anywhere but my
documents. All other workstations do not have this limitation.
Where is there a setting for allowing these permissions. My server
policies do not include these restrictions I don't know where the
pc is getting then even though it says it is using the domain
security policies which is what everyone else is using with no
problems.

See above, re rsop.msc and your event logs.

What's different about it?
Nothing. Same operating system, same user logging onto workstation,
same software as all other pc's, same domain controller and server.

I use the security policy to handle most of our needs but the firewall
is so restrictictive it becomes cumbersome to add all the exceptions.

For what? How many apps do you have that require unsolicited *inbound*
access to your desktops? I'd sure hope it isn't many.

And remember, you set the exceptions via.....group policy. :-)

I will probably turn on the firewall on one of the workstations and
see what needs to be allowed before I put it in the global policy.
Good point.

Yep - try it as a test.

I ran the rsop.msc but can't figure out where the file access rights
are.

They aren't in there. That's NTFS. It will help you isolate the problem if
you have policy errors. but check your NTFS security and event logs.


.



Relevant Pages

  • Re: [fw-wiz] Firewalling at the domain users level instead of network level
    ... security policy. ... > alternatives in terms of security. ... > so different from the ISO-17799 consultants and certifications we were just ... My home firewall isn't a certified product. ...
    (Firewall-Wizards)
  • Re: [fw-wiz] Where do firewall Admins Sit in An Company
    ... Security should also be reviewing logs and usage as well. ... constant review and maintenance and firewall policy is no different. ... If the firewall administrators sit in a non-security group what type ...
    (Firewall-Wizards)
  • Re: firewall
    ... I was able to disable server control over my workstations firewall. ... Configuration of the desktop Windows Firewall is managed via Group Policy. ... Advanced Management> Group Policy Management in the SBS Server Management ...
    (microsoft.public.windows.server.sbs)
  • Re: Suggest firewall for Win98se+ICS(dialup)+NAV
    ... > gateway for a peer-to-peer LAN with two workstations behind it? ... > Whatever software firewall you select should be capable of at least using ... There are no apps at all on the box I'm building for the client ...
    (comp.security.firewalls)
  • Re: Questions About Windows Firewall and Domain Policy Enforcement (Updated Info)
    ... I have a Windows 2000 domain that has 200 workstations most of which are ... If we enable the firewall on the workstations then the domain ... SP2 settings on firewall activation). ... long as there is no Standard Profile configured. ...
    (microsoft.public.windows.group_policy)