Windows Tip: Managing Windows Firewall in mixed environments

March 12, 2007, 10:46 AM —  ITworld.com — 

Send your Windows question to Mitch today! | See other Windows tips



Those enterprises that have begun testing Windows Vista for deployment will have noticed many differences between how this new version of Microsoft Windows is managed compared with the previous version Windows XP. One area of difference is managing the Windows Firewall, for not only has the Windows Firewall been significantly enhanced in Windows Vista with outbound filtering and IPsec integration, there is also a new management tool (the Windows Firewall with Advanced Security Policy snap-in) and new Group Policy settings for managing the firewall.



If you migrate all the desktops in a given organizational unit to Windows Vista, you can simply manage the firewall on these computers using the new Group Policy node found under Computer Configuration\Windows Settings\Security Settings\Windows Firewall With Advanced Security. But what if your OU will contain a combination of Windows XP and Windows Vista computers? What's the best way to use Group Policy to manage the Windows Firewall on these computers? Here's a brief answer taken with permission from the soon-to-be-released Windows Vista Resource Kit:


Windows Vista introduces a lot of new and exciting functionality in Windows Firewall. However, policy created by the new management console, Windows Firewall with Advanced Security is not understood by earlier versions of Windows. Using WMI filtering to selectively apply policy to a Group Policy object (GPO) allows you to manage this mixed environment. Through Group Policy Management Console (GPMC), create two GPOs. Use a WMI query to target one of the GPOs to only computers running a version of Windows prior to Windows Vista. In this GPO, create a firewall policy using the Windows Firewall Administrative Template (located under Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall). Target the second GPO to Windows Vista and later computers. Configure the firewall policy for this GPO using the Windows Firewall with Advanced Security snap-in (located under Computer Configuration\Windows Settings\Security Settings\Windows Firewall with Advanced Security).



There are several reasons why we recommend that you take the split GPO approach to firewall management even though Windows Vista understands the Windows Firewall Administrative Template policy. First, by using the Windows Firewall with Advanced Security snap-in for policy configuration instead, you can take advantage of the flexibility and granularity of the new functionality, allowing for rules that are scoped much more than they could be when you use the Windows Firewall Administrative Template. Additionally, Windows Firewall with Advanced Security ships with a number of rule groups that are already configured to provide features and experiences in Windows Vista the network access they need. Trying to translate these rules into the Windows Firewall Administrative Template is in some cases not possible and in other cases would result in a rule that exposes much more attach surface than the Windows Vista equivalent rule. Finally, earlier versions of Windows Vista may be running different programs or updated versions of the programs for Windows Vista may have different networking requirements, so this split helps ensure that each computer gets only the rules it needs.

The above is one of many great tips you'll find in the Windows Vista Resource Kit, and one reason you'll find this book an invaluable resource is because this particular insight (and dozens and dozens of others in the book) was contributed by someone on the Windows Vista product team at Microsoft. These "from-the-source" insights are designed to help IT pros understand how Windows Vista works under the hood and also provide best practices for deploying, managing and troubleshooting different features of the platform.

 

ITworld.com

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Resources
White Paper

Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.

Webcast

Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.

White Paper

Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.

Free stuff

Crimeware: Understanding New Attacks and Defenses
By Markus Jakobsson, Zulfikar Ramzan
Published Apr 6, 2008 by Addison-Wesley Professional. Part of the Symantec Press series.
Enter now! | Official rules | Sample chapter

Securing VoIP Networks: Threats, Vulnerabilities, and Countermeasures
By Peter Thermos, Ari Takanen
Published Aug 1, 2007 by Addison-Wesley Professional.
Enter now! | Official rules | Sample chapter

Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

More Resources