Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


May 2004

Meet Windows Firewall

Get the lowdown on XP SP2's successor to ICF
RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

A GPE note. If you're creating a domain-based GPO to control Windows Firewall, you'll need to do a little preparation. Because the Windows Firewall policy settings are all new, your Windows Server 2003- or Windows 2000-based domain controller's (DC's) copies of GPE (gpedit.msc,) almost certainly won't display the Windows Firewall policy settings. (I say "almost certainly" because a Windows 2003 system that's running Windows 2003 SP1—which is supposed to ship some time this year—would have the settings. That service pack will modify Windows 2003's firewall in the same way that XP SP2 modifies XP's firewall.)

To create a domain-based GPO that includes the new Windows Firewall settings, load the Windows 2003 administration tools onto an XP box that has SP2 installed. Open the Microsoft Management Console (MMC) Active Directory Users and Computers snap-in (for a site policy, open the MMC Active Directory Sites and Services snap-in) at that XP system. You can then create or edit a GPO that includes the new policy settings.

Configuring mobile and domain profiles from the command line. Domain-based Windows Firewall policies are great, but users who aren't yet running AD are likely to turn to batch files for help. The mobile and domain profiles make Windows Firewall more attractive, but can you control them from the command line? The answer is yes—you can even set up mobile and domain profiles from the command line.

To control Windows Firewall's behavior in a particular profile, just add the profile= parameter to the Netsh Set Opmode command, followed by the keyword current, all, corporate, or other. The current keyword tells the system to make the change to the active profile. The all keyword means make this change to both profiles. Less obvious are the corporate keyword, which changes the domain profile, and the other keyword, which changes the mobile profile. (I sometimes get the idea that lots of people at Microsoft are working on Windows Firewall and that they don't all talk to one another.)

Suppose I want to use the command line to set up a system that turns off Windows Firewall while the system is connected to a domain and turns on the firewall otherwise. The following two commands accomplish that task:

netsh firewall ipv4 set opmode 
  mode=disable profile=corporate
netsh firewall ipv4 set opmode 
  mode=enable profile=other

Digging Deeper
Armed with these basics, you can get started using Windows Firewall's power. But let me stress two things. First, I don't recommend turning off the firewall in mobile mode. Second, I think that enabling the firewall isn't a bad idea even inside a domain.

We've just scratched the surface of Windows Firewall's abilities, and they really are worth understanding better. In an upcoming article, I'll dig deeper.

End of Article

   Previous  1  2  [3]  Next  


Reader Comments
I've really been concerned about having Firewall enabled inside my domain, but we've been doing some testing and it seems ok. This article helps convince me that we're doing the right thing.

itgeeks October 27, 2004 (Article Rating: )


well i think is a bloody awful thng
i cant even get it to work on a simple internet machine with one attached pc using windows network.. only one machine can access interent at a time if i have file sharinf turend off..turned on it all goes potty on its own


Anonymous User February 22, 2005


well i think is a bloody awful thng
i cant even get it to work on a simple internet machine with one attached pc using windows network.. only one machine can access interent at a time if i have file sharinf turend off..turned on it all goes potty on its own


Anonymous User February 22, 2005


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
WinInfo Short Takes: Week of November 9, 2009

An often irreverent look at some of the week's other news, including some more Windows 7 sales momentum, some Sophos stupidity, Microsoft's cloud computing self-loathing, more whining from the browser makers, Zoho's "Fake Office," and much, much more ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

Windows 7 Sets Sales Record

Microsoft CEO Steve Ballmer described Windows 7's first ten days of sales as "fantastic" while in Japan yesterday. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events WinConnections and Microsoft® Exchange Connections

Deep Dive into Windows Server 2008 R2 presented by John Savill

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement