Friday, 23 August 2013

Windows Firewall deployed by GPO detecting Public NL

Windows Firewall deployed by GPO detecting Public NL

Am struggling with Server 2008 R2 NLA and the Windows Firewall.
Currently we are testing rolling out Windows Firewall via GP and have a
test server that enables the firewall for Domain, Private and Public.
Public and Private are set to lock down while the Domain has the default
profile (unsolicited Inbound blocked, Outbound allowed). The settings
applied correctly and there was no loss of communication. Everything
looking hunk dory.
Latest Windows Updates caused an issue so we reverted to a snapshot (VM
running on ESXi 5). Now the firewall is connecting under the Public
profile and all communication is broken. Due to GP controlling the policy
I cannot disable the policy or reset the policy on the box. The only
solution we have found is to stop the firewall service and remove the
computer from the GPO. This then allows normal communication.
I had a google and have seen that in Jan 2012 there was a hotfix
(KB2524478) that resolved this issue but that is already deployed and the
hotfix states it is not needed. I am guessing something in the NLA is
incorrectly associating itself with being on a Public connection but I
cannot see anyway to override the network location to the Domain profile.
Does anyone have any suggestions about how I might be able to troubleshoot
this further? I am loathe to amend the procedure to disable the service,
reboot and then re-enable as I feel this is a workaround.

No comments:

Post a Comment