• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Windows Firewall Question

Morphius143

Weaksauce
Joined
Nov 30, 2004
Messages
72
This will sound like a stupid question, and seemingly pointless, BUT I am getting endless grief at work for it. :mad:

I know that some settings in XP are controlled by individual user profiles (user.dat in c:\documents and blah blah blah) and some are machine wide...

Now I am sure that windows firewall being on or off is a machine wide setting, whereas my boss says it can be set in the default profile, can anyone say for sure? I have browsed the cursed MS site yet still cant find proof of where it hides (apart from that it can be set by a group policy)

If it makes any difference we are running domains, with 2000 server or 2003 server.

If anyone can shed light on this, or even better has a link to Beyond All Doubt proof, I would be eternally gratefull
 
The local admin profile can disable it for all profiles below it. You can also set domain permissions to turn that gay ass thing off as it causes more problems then it fixes but I've long forgotten where that thing hides at.
 
IceWind said:
The local admin profile can disable it for all profiles below it. You can also set domain permissions to turn that gay ass thing off as it causes more problems then it fixes but I've long forgotten where that thing hides at.

I have it enabled and controlled via group policy, with the ports open that my workstations need. I haven't had any trouble with it, although I feel much more confident in my external safeguards than the windows firewall.

I am curious, what have you had it mess up?
 
It is blocking access to network computers (what it is meant to do) but we are two levels behind a government firewall so generally my boss cant be bothered with running it. Joining the domain automatically turns it back on and sometimes that gets forgotten.

Group policy is the way to go... if it were my network (well, my 10 networks, on different sites, all seperate) i would set up a group policy, but i am the lowest techy, with a boss who is nervous of change, or the 22yr old who was employed to help him out.

To be honest, once I can prove that the tick box in the control panel of the computer will disable it for that entire computer regardless of who logs on (doesnt matter that they can just enable it again, they cant see the control panel) I can 'politely' point this out, and let him know that he doesnt have to set it for each user profile.

Just to clarify the situation, the servers are all primary education ones, and so the desktop pcs have to be locked down and look identical. We often have to reset the default profile, and wipe the profiles of users that have been saved in c:\documents blah blah to make sure that software etc doenst ask for key codes, or setup options for the kids (kids software in general is designed using tech based on making it run on win 95, not xp), and to hide the hidden files etc. I just want to know for definate that windows firewall doesnt care who logs on, what their user.dat file looks like, if it is disabled from the control panel once by the admin, it will do it for every person underneath.

MS's site hints at this... never refering to users once (20 pages of config options later to find that out) but wont clarify...

Sorry for the long winded explination of the situation here. I am grafetull for anything that stops me listening to him if he is wrong, or sets me right
 
Back
Top