RE: Group Policy Question on firewalls

From: Laura A. Robinson (laurarobinson_at_earthlink.net)
Date: 09/22/05

  • Next message: layne_at_elsenot.com: "ElseNot Project"
    To: "'Russell Morrison'" <rmorrison@axys.net>, "'Focus-MS'" <focus-ms@securityfocus.com>
    Date: Wed, 21 Sep 2005 18:42:06 -0400
    
    

    Put your workstations into a separate OU and create the policy there. You
    don't have to set all policies at the domain level; in fact, the only
    policies that *must* be set at the domain level are the domain
    password/Kerberos policy settings.

    Laura

    > -----Original Message-----
    > From: Russell Morrison [mailto:rmorrison@axys.net]
    > Sent: Wednesday, September 21, 2005 2:04 PM
    > To: 'Focus-MS'
    > Subject: Group Policy Question on firewalls
    >
    > To all;
    >
    > I would like to turn on the Windows Firewall application on
    > all network connected desktops and have seen where this can
    > be done within the Domain Group Policy. However, I don't
    > want to also turn on the firewalls on my Windows 2003 servers
    > as this will likely block normal network traffic. Is there a
    > setting, either within the Domain Group Policy that allows me
    > to differentiate between servers and desktops for firewalls,
    > or is there a setting within the server local security policy
    > or server registry that would allow me to disable that
    > service on the server? I am running 2003 AD,
    > 2003 servers with latest patches, and a mixtures of XP and
    > 2000 desktops also running latest patches.
    >
    > Thanks for any help.
    >
    > R
    >
    >
    >
    > **************************************************************
    > *********
    > Confidentiality Notice: This e-mail message, including any
    > attachments, is for the sole use of the intended recipient(s)
    > and may contain confidential and privileged information. Any
    > unauthorized review, use, disclosure or distribution is
    > prohibited. If you are not the intended recipient, please
    > contact the sender by reply e-mail and destroy all copies of
    > the original message plus any attachments.
    > **************************************************************
    > *********
    >
    > --------------------------------------------------------------
    > -------------
    > --------------------------------------------------------------
    > -------------
    >

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: layne_at_elsenot.com: "ElseNot Project"

    Relevant Pages

    • Re: Repost - WSUS help required for Server updates
      ... Hi Rob - if you look in the Group Policy Management Console, ... If you delete the policy under the domain level where you ... servers are set to download and notify. ... installation and approve for updates together with the client PC's. ...
      (microsoft.public.windows.server.sbs)
    • Re: Account Lockout threshold
      ... All are window 2000 advanced servers with Service pack 3, ... Domain Contoller Security Policy - Account lockout threshold ...
      (microsoft.public.security)
    • Re: Security templates and IUSR account log on locally
      ... the Enterprise security template for Member Servers breaks IIS6 anon ... the guideline is to apply the member servers baseline policy and then the ... web servers policy. ... You may also want to revisit the download for the W2k3 Security Guide as ...
      (microsoft.public.inetserver.iis.security)
    • Re: Preventing users from c onnecting to shares NOT on the domain..
      ... First condition would be to set "Require Security" policy to "Restricted ... These computers could be excluded by IP address, ... > The servers might be located on the same subnet of some of the clients. ...
      (microsoft.public.win2000.networking)
    • Re: Preventing users from c onnecting to shares NOT on the domain..
      ... First condition would be to set "Require Security" policy to "Restricted ... These computers could be excluded by IP address, ... > The servers might be located on the same subnet of some of the clients. ...
      (microsoft.public.win2000.security)