Firewall Forums

Go Back   Firewall Forums > Windows > HOW-TOs for Windows
User Name
Password
Portal Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

HOW-TOs for Windows If you have a HOW-TO for any Windows Firewalls, Security, Virus, Spam or the likes you can post them here.

  #1  
Old 08-19-2007
gale
 
Posts: n/a
Default Few GPO Windows Firewall Settings that have 2 registry values associated with them

In PolicySettings.xls - a spreadsheet that lists all GPO settings available at http://www.microsoft.com/downloads/d...displaylang=en, some
settings have multiple registry value paths associated with them.
[In GPO Editor , when enabling the settings listed below, a user must specify more than whether the setting is Enabled/Disabled ]

Are all these registry values required to store each Windows Firewall GPO Setting ? For instance::

1.For the policy setting - Windows Firewall: Allow remote administration exception;
there are 2 registry values associated :
1] HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\D omainProfile\RemoteAdminSettings!Enabled,
2] HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\D omainProfile\RemoteAdminSettings!RemoteAddresses
Are both neccessary for the GPO setting to be Enabled. To determine if the setting is Enabled, isn't the first 1 sufficient?

Similar case for :

Windows Firewall: Allow file and printer sharing exception

Its 2 registry values are:
1] HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\D omainProfile\Services\FileAndPrint!Enabled,
2] HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\D omainProfile\Services\FileAndPrint!RemoteAddresses

If the 1st Registry value is set to enabled, is it neccessary to check for the Address List.What will the behaviour be , if only the 1st registry value is present?

2. On enabling the Logging setting in gpedit.msc , 2 registry values get created - LogFileSize & LogFilePath & on disabling the setting, both registry values get deleted

If 1 registry value say LogFileSize is deleted, is Logging enabled/disabled effectively? In GPO Editor, the setting before the value was deleted is maintained.i.e. To check if logging is enabled using a script, are the values of both registry values[LogFileSize & LogFilePath] required?
Reply With Quote
  #2  
Old 06-03-2010
HowardMd HowardMd is offline
Junior Member
 
Join Date: Jun 2010
Posts: 3
HowardMd is on a distinguished road
Default Re: Few GPO Windows Firewall Settings that have 2 registry values associated with them

Good questions.
This is just my opinion base on my experience:
1. If you just enabled the remote admin without assigning the address, then the service will ne available to all address and will create security leak.
2. Same case with no. 1
3. I think windows has default values. So if you don't set the logfilesize windows will set it to its default.

I hope this help.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -6. The time now is 03:49 PM.



All Trademarks are copyrighted to their respective owners.
Powered by vBulletin Version 3.5.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright 2006 (c) Firewall Forums