|
Posted by David on June 13, 2007, 10:45 am
Please log in for more thread options
1) when host firewall is enabled (server 2k3 R2, sp2) and computer is a
domain member, are the standard and domain profiles combined or is it only
the profile listed as current thats in effect? (I'm assuming they don't
combine, but am not positive, so looking for verification)
2) also, I'm assuming when you make exceptions on individual interface
(advanced -> settings button) that they are combined with whatever profile
is in effect? Looks this way when looking at 'netsh firewall show config'
command output because is breaks down the settings by profile, then lists
the individual interface config at the end like:
domain profile configuration (current):
service configuration
allowed programs
port configuration
icmp configuration
standard profile configuration:
service configuration
allowed programs
port configuration
local area connection configuration:
service configuration
allowed programs
port configuration
above shows example categories, (only shows if config exists in the
category, so you may not see all) and my point for showing it is that the
individual interface settings are displayed just like a profile, or at the
same 'level' of a profile. Am I wrong to assume then that they are like a
profile but combined with whichever global profile is in effect, either the
domain or standard? (that assumes my first assumption above about those 2
profiles combining is correct, they don't)
|