RE: XP-SP2 "Feature"

From: DeGennaro, Gregory (Gregory_DeGennaro_at_csaa.com)
Date: 09/08/04

  • Next message: Sergey V. Gordeychik: "RE: RKDetect - behaviour based rootkit detection (updated)"
    Date: Wed, 8 Sep 2004 14:35:03 -0700
    To: "Ian Miller" <miller@ucalgary.ca>
    
    

    Ian,

    I recently took a class on applying MS security features and I did not
    hear such a thing. In fact, the book showed us how to apply ipsec
    policy and deny or permit icmp traffic. After applying the rule to
    block, icmp did not work but GPO still worked.

    Regards,
     
    Greg DeGennaro Jr., CISSP, CCNP
    Systems Engineer

    -----Original Message-----
    From: Ian Miller [mailto:miller@ucalgary.ca]
    Sent: Wednesday, September 08, 2004 7:32 AM
    Cc: focus-ms@securityfocus.com
    Subject: Re: XP-SP2 "Feature"

    What about Group Policy? Does anyone know if XP/2K Pro require ICMP to
    be open across firewalls? The reason I ask this is we have been told
    (but unable to confirm) by other sources that ICMP must be available in
    order for Group Policy to work. If ICMP is not required (could you
    please indicate in your response) what work-arounds are necessary in
    order for Group Policy (both Computer and User) to work across
    firewalls.

    >
    > Thanks.
    >
    >>

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Sergey V. Gordeychik: "RE: RKDetect - behaviour based rootkit detection (updated)"

    Relevant Pages

    • Re: XP-SP2 "Feature"
      ... What about Group Policy? ... Does anyone know if XP/2K Pro require ICMP to ... order for Group Policy to work across firewalls. ... >>Systems Analyst ...
      (Focus-Microsoft)
    • Re: ICMP Ping and Group Policy Update
      ... sounds like folks pretty much confirmed that blocking ICMP blocks ... Group Policy updates for at least some users. ... stopping 40 byte packets. ...
      (NT-Bugtraq)
    • Re: ICMP Ping and Group Policy Update
      ... we blocked ICMP Pings to & from our VPN. ... > it appears that this also has disabled group policy updates for remote ... when a client machine attempts to connect to ... ICMP pings to the DC in order to test connectivity and link speed. ...
      (NT-Bugtraq)
    • Re: ICMP Ping and Group Policy Update
      ... Blocking all ICMP is not the proper way to mitigate this threat. ... ICMP Ping and Group Policy Update ... when a client machine attempts to connect to ... ICMP pings to the DC in order to test connectivity and link speed. ...
      (NT-Bugtraq)