Re: Change SP2 firewall profile from CLI



Hi Jeff.

My understanding is that unless you specify a profile the default profile is
used for the option you set in set opmode mode and is not to change mode.
The possibilities are current, standard, domain, and all. So I suspect that
your command is actually setting the Windows Firewall to be enabled in the
standard profile. As far as I know the profile used can only be determined
on whether or not the operating system detects a domain controller for it's
domain on the network it is connected to and it supposed to be periodically
be determined by the network location awareness service.

Steve


"Jeff Vandervoort" <jeffv @ jrvsystems dot com> wrote in message
news:%23KhPS8D4GHA.600@xxxxxxxxxxxxxxxxxxxxxxx
Windows XP SP2 client in SBS2003 SP1 domain. XP client firewall settings
set
by GPO.

When the computer is connected to the SBS network, and logged on to with
the Administrator account, NETSH help leads me to believe that the
command...
netsh firewall set opmode mode = enable profile = standard
...should change the firewall profile from Domain to Standard.

And when I issue the command, NETSH responds with "Ok." as though it's
actually done something useful. Yet this command...
netsh firewall show opmode
...shows that the Domain profile remains the current profile.

I've also tried it with a Scheduled Task that runs in the SYSTEM account,
with the same result.

In the GPO, "Windows Firewall: Protect all network connections" is set to
Not Configured for both profiles. I can enable and disable the firewall
from the NETSH command line, just can't switch profiles.

What's up with that?

--
Jeff Vandervoort
JRVsystems



.



Relevant Pages

  • Re: Change SP2 firewall profile from CLI
    ... You could try configuring the standard profile with the exceptions you need ... It only gives me the choice of enabling or disabling the firewall for my ... The possibilities are current, standard, domain, and all. ... NETSH help leads me to believe that the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Installing a 360 Media Center Extender
    ... The Windows firewall has the notion of a Public profile and a Private ... for use when you're connecting to hot spot wireless networks and the like). ... try directly connecting your PC and Xbox again, ...
    (microsoft.public.windows.mediacenter)
  • Re: GPO controlled firewall incorrectly ON due to Standard instead of Domain Profile
    ... laptop and resume it, or turn off/turn on the laptop when you connect to ... applied and the firewall will be turned on. ... Group Policy is segmented into two applications, the domain profile and the ... Windows XP Pro / Firewall client is using a non configured Windows Firewall ...
    (microsoft.public.windows.group_policy)
  • XP SP2 Firewall selects Standard profile when computer is properly connected to domain network
    ... the Firewall settings are exactly what is configured in the Group Policy ... Standard firewall profile has no Exceptions. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Windows Firewall Turned on Automatically
    ... > boxes not correctly detecting the correct firewall profile. ... > selecting which domain profile to use, since we do not have the ... rather than disabling it outright? ...
    (microsoft.public.windowsxp.security_admin)