RE: Windows firewall scopes for notebook users ex office...

From: Mika Weckström (mika.weckstrom_at_receptum.fi)
Date: 03/24/05

  • Next message: Matt Bazan: "quarantine vpn clients"
    Date: Thu, 24 Mar 2005 18:42:56 +0200
    To: Zack Schiel <ZSchiel@blueandco.com>
    
    

    > I believe the "domain" settings are only used when the machine can
    > actually contact the domain. Otherwise, the stronger settings are used.

    WinXP SP2 firewall check's the connection specific DNS-suffix from any
    connection it has when connected. If the suffix is the same (in any connection)
    from where GPO:s where last downloaded it thinks that it is connected to domain.

    You can try it yourself. Change the connection spesific DNS-suffix from TCP/IP
    properties and voila, Your firewall has changed the profile.

    So it windows firewall is also very easy to cheat ;-)

    Kind Regards
    Mika Weckström

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Matt Bazan: "quarantine vpn clients"

    Relevant Pages

    • Re: I am having connectivity problems
      ... firewall and turned ON Windows firewall. ... When I tried to install SP2 I was unable to get it thru Windows Update. ... does the connection problem persist? ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: Serious Security Issue in Windows XP SP2s Firewall
      ... Subject: AW: Serious Security Issue in Windows XP SP2's Firewall ... If you update a WinXP SP-1 with enabled Internet ... Connection Firewall ...
      (Focus-Microsoft)
    • RE: Serious Security Issue in Windows XP SP2s Firewall
      ... file and printer sharing is available for network login from any network (I ... Internet Connection Sharing of the PC has to be disabled." ... Serious Security Issue in Windows XP SP2's Firewall ...
      (Focus-Microsoft)
    • Re: Still cant connect to RWW or OWA remotely
      ... No, I don't have a 3rd party firewall, and it's a pretty plain vanilla WinXP ... Connected to the network like the other workstations, ... I could go to any workstation and connect to them just fine. ... match the broadband connection, the two NIC firewall, the remote ...
      (microsoft.public.windows.server.sbs)
    • Re: Big hole??
      ... > firewall then even they can't get in, ... > supposedly safe SP2 for Windows XP invites any Internet ... > Connection Sharing of the PC has to be disabled. ... > in fact is a common configuration and not a rare sight. ...
      (microsoft.public.windowsxp.general)