Click here to get back home

SBS 2003 - XP SP2 - Firewall GPO issues

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
SBS 2003 - XP SP2 - Firewall GPO issues Mark Simons 12-07-2005
Posted by Mark Simons on December 7, 2005, 1:25 pm
Please log in for more thread options
I have set up port exceptions in SBS 2003 in the Small Business Server
Windows Firewall GPO as well as Default Domain Policy. They show up in the
XP SP2 registry as seen here:


[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts\List]
"80:TCP:*:Enable:Web-Mark"="80:TCP:*:Enable:Web-Mark"
"135:TCP:*:Enabled:Offer Remote Assistance - Port"="135:TCP:*:Enabled:Offer
Remote Assistance - Port"
"2967:TCP:*:Enable:SAV2"="2967:TCP:*:Enable:SAV2"
"2967:UDP:*:Enable:SAV1"="2967:UDP:*:Enable:SAV1"
"38293:TCP:*:Enable:SAV3"="38293:TCP:*:Enable:SAV3"
"38293:UDP:*:Enable:SAV4"="38293:UDP:*:Enable:SAV4"
"80:TCP:*:Enable:Web-Mark2"="80:TCP:*:Enable:Web-Mark2"

Only the Offer Remote Assistance - Port show up when you look at the
exceptions in Firewall settings and none of the rest show up, or work.

I tried the same thing on another SBS 2003 machine and they propergated just
fine.. Any ideas?

Thank you.




Posted by Steven L Umbach on December 8, 2005, 12:37 am
Please log in for more thread options
Try configuring the Windows Firewall in the default domain controller Group
Policy that is linked to the domain controller container. That is how it
works in an AD domain so I am not sure if SBS also has a domain controller
container or not. You can also use the Resultant Set of Policy mmc snapin on
the domain controller to see what Group Policy settings are applying to the
domain controller and what Group Policy is applying the setting. --- Steve


>I have set up port exceptions in SBS 2003 in the Small Business Server
> Windows Firewall GPO as well as Default Domain Policy. They show up in
> the
> XP SP2 registry as seen here:
>
>
>
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts\List]
> "80:TCP:*:Enable:Web-Mark"="80:TCP:*:Enable:Web-Mark"
> "135:TCP:*:Enabled:Offer Remote Assistance -
> Port"="135:TCP:*:Enabled:Offer
> Remote Assistance - Port"
> "2967:TCP:*:Enable:SAV2"="2967:TCP:*:Enable:SAV2"
> "2967:UDP:*:Enable:SAV1"="2967:UDP:*:Enable:SAV1"
> "38293:TCP:*:Enable:SAV3"="38293:TCP:*:Enable:SAV3"
> "38293:UDP:*:Enable:SAV4"="38293:UDP:*:Enable:SAV4"
> "80:TCP:*:Enable:Web-Mark2"="80:TCP:*:Enable:Web-Mark2"
>
> Only the Offer Remote Assistance - Port show up when you look at the
> exceptions in Firewall settings and none of the rest show up, or work.
>
> I tried the same thing on another SBS 2003 machine and they propergated
> just
> fine.. Any ideas?
>
> Thank you.
>
>
>



Similar ThreadsPosted
Windows 2003 enterprise CA issues - RPC server is unavailable. February 12, 2008, 3:27 am
Firewall of Windows 2003 October 2, 2005, 1:31 am
Windows 2003 firewall November 22, 2005, 12:09 pm
Is Windows 2003 firewall safe? March 23, 2006, 8:28 am
Win 2003 Firewall Problem. Ahhh January 4, 2008, 2:55 pm
Antivirus+Firewall for Windows Server 2003 May 25, 2006, 9:59 am
Saving a Windows 2003 Firewall Configuration? December 15, 2006, 11:28 pm
Simple question regarding Windows 2003 Firewall April 1, 2007, 11:35 pm
Windows 2003 built-in firewall prevents AD from synching across DCs December 8, 2005, 11:24 am
properly configured windows 2003 server OK without a hardwre firewall? November 24, 2007, 12:00 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap