Re: Firewall profile switching



Thanks Steven, that page was helpful!

I had tried a gpupdate /force after connecting to the outside force the
first time around and this second time with no luck, i'm still on the domain
profile. My plan now is to wait some time, as even a release / renew on the
new network doesn't get me to the standard profile.

From that page:

"If the last-received Group Policy update DNS name does not match any of the
connection-specific DNS suffixes of the currently connected connections on
the computer that are not PPP or SLIP-based, then the computer is attached to
another network."

an ipconfig /all shows no trace of my company's DNS suffixes or IPs.

"Windows uses this network determination process during start up and when it
is informed by the Network Location Awareness service that network settings
on the computer have changed."

I guess this is my next step - to see how this works, and what exactly it
does. I'll let everyone know what happens for posterity's sake.

Thanks again!

-Pete

--
======================
http://petekemble.com


"Steven L Umbach" wrote:

The link below helps to explain the network determination behavior though
there is some dispute on exactly how it works. What I would try after you
remove the computer from the network to run gpupdate /force on the computer
to see if that makes a difference. If that works then do the procedure again
and try using just gpupdate. If gpupdate /force or gpupdate work then if
you need to you can change the Group Policy refresh interval for computer
configuration and policy processing [if needed] that can speed up the
changing of profiles for Windows Firewall with the understanding you want to
do that only for computer that need it as reducing the interval and
particular policy processing to force Group Policy to be reapplied at each
refresh will increase network usage. --- Steve

http://www.microsoft.com/technet/community/columns/cableguy/cg0504.mspx

"sounddoc" <sounddoc@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:57F6D6FC-275D-4FA4-BC8B-D68687FBB617@xxxxxxxxxxxxxxxx
Hello all,

I'm currently testing a GPO to hopefully go live that will enable /
disable
the windows firewall depending on the location of our users. The GPO
itself
is fine - what i'm having trouble with is switching profiles
automatically.

If I boot off the network, then the standard profile is applied just fine.
once i connect to the network the domain profile is applied almost
immediately. the problem is though, that once i disconnect again from the
network, the domain profile stays current. even when i connect to an
outside
network, the domain profile stays active. is this supposed to happen? am i
not waiting long enough for the profile to switch back to standard?

thanks very much!
-Pete
--
======================
http://petekemble.com



.



Relevant Pages

  • Re: Installing a 360 Media Center Extender
    ... When your PC is connected directly to the Xbox (effectively taking it off ... your home network), the firewall will switch to the public profile. ... try directly connecting your PC and Xbox again, ...
    (microsoft.public.windows.mediacenter)
  • Re: Browsing Network
    ... are you sure you have the correct permissions on these network ... Do the machines that you are connecting to pass the nltest /sc_query test? ... > connect them to any network resources such as printers. ... > I have tried deleting the profile and re-creating it, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Connecting to Wireless Networks
    ... > connecting to my home wireless network. ... access point using a different "profile", ...
    (Fedora)
  • Re: VPN problems
    ... >>I have three other computers who connect via VPN into our network and ... >> profile, ... She is connecting to the internet using ...
    (microsoft.public.win2000.networking)
  • Re: Firewall profile switching
    ... The link below helps to explain the network determination behavior though ... and try using just gpupdate. ... particular policy processing to force Group Policy to be reapplied at each ... If I boot off the network, then the standard profile is applied just fine. ...
    (microsoft.public.windowsxp.security_admin)