• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Windows Firewall via GPO

BigJayDogg3

[H]ard|Gawd
2FA
Joined
Jul 21, 2009
Messages
1,678
We have an application that creates its own directory and places a version of Java under

c:\users\[user]\blah\jre\1.7.0_xx\bin\java.exe

This application ties back to an internal server, and after every server side update, it pushes a client update, often tied with a newer Java version.

The problem we see is a feature of the program gets blocked since Windows firewall is seeing a program under the user's profile trying to connect to an external server and creates a couple block rules. The question is how do we allow this through Windows firewall without having to touch each client PC?

I tried using %USERPROFILE%\blah...\java.exe inside a new GPO. When I go into my computer's Firewall, I see the new rule along with the old rules. Deleting the old rules and reopening the application causes the Windows Firewall box to pop back up, and the creation of two new block rules. I did change %userprofile% to "C:/users/bigjaydogg3/[...]java.exe" and got the expected behavior.

Help?
 
A reboot of all computers will be needed to make sure they get the new policy once it is set.
 
Get everything working on one computer export the policy then import into GP for all the computers.
http://www.howtogeek.com/100409/gro...ndows-firewall-with-a-gpo/?PageSpeed=noscript

Sorry for taking so long to get back.

I don't quite think that will work here, as each user will have their own "version" of java unpacked in their user directory. Setting a single location as the source. If this operates as I think it will, this won't solve the issue.

To clarify, every time a new user uses this application, it spits out another instance of Java in their user directory. I want Windows Firewall to allow this connection through, while still prompting/blocking other new connections.

EDIT: Since the entirety of my old post got deleted, this isn't something that just can't be done. This program will have to be let through the firewall. The question is whether or not we'll have to go computer-to-computer to make the change, or if I can push this out centrally. I'd like as few touches as possible, but it doesn't look like a one-touch solution is possible.
 
Last edited:
ok use a script to get the user profile directory then apply the rule using netsh you can do this with a login script.
You need to check and see if it will apply it multiple times if you need to remove it then add it each time.
If it ignores it if its already there you just need to add and no remove.
 
Back
Top