Warning: iconv_mime_decode() [function.iconv-mime-decode]: Malformed string in /home/secureg/public_html/lib/standard.lib.php on line 2251
Enabling windows firewall on 2003 server remotely
Enabling windows firewall on 2003 server remotely

Enabling windows firewall on 2003 server remotely

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Enabling windows firewall on 2003 server remotely Jason 12-27-2005
Posted by =?Utf-8?B?SmFzb24=?= on December 27, 2005, 3:39 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

I have windows 2003 SP1 server that is colocated, managed thru PCAnywhere
and terminal services only (I do not have physical access to the box). I
also do not have another 2003 box locally that i can test this on. Im
wondering when the firewall starts when I enable it. At the moment if I
attempt to go into the Windows Firewall section of the control panel, it asks
me to start the Internet Connection Sharing service and Im reluctant as Im
not sure if this will block me out of Terminal Services.

Can anyone tell me if I start this service, will I have a chance to add
exceptions before the firewall starts? So that I can add a terminal services
exception to allow me to manage the server remotely without having to make a
call to the ISP while the server is down.

Thank you,
Jason

Posted by =?Utf-8?B?SWFu?= on December 28, 2005, 4:09 am
If you were  Registered and logged in, you could reply and use other advanced thread options
The firewall exceptions are controlled by registry keys. They take the
general form:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"<PORT>:TCP"="<PORT>:TCP:*:Enabled:PC Anywhere"

Where 'PORT' is replaced by the port number.

Therefore it should in principle be possible to set an exception on one
machine, examine the registry entry it creates, and transfer it via a .reg
file before the firewall is activated. AFAIK XP Pro has the same rules.
(unless anyone knows otherwise)

HST do be prepared for the risk of losing your connection, better to do this
kind of thing onsite!



Posted by Steven L Umbach on December 28, 2005, 2:35 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Most likely you will be locked out once you enable the firewall assuming
there is no exception for TS [port 3389 TCP] which most likely there will
not be. Two possibilities come to mind. You could try using the Security
Configuration Wizard [see link below] to configure and then enable the
Windows Firewall or configure local Group Policy being sure to configure the
exceptions first. Either way I would want to test any solution out on a test
server I have access to if it is going to be a big problem if you lock
yourself out. --- Steve

http://www.microsoft.com/windowsserver2003/technologies/security/configwiz/default.mspx

> Hi,
>
> I have windows 2003 SP1 server that is colocated, managed thru PCAnywhere
> and terminal services only (I do not have physical access to the box). I
> also do not have another 2003 box locally that i can test this on. Im
> wondering when the firewall starts when I enable it. At the moment if I
> attempt to go into the Windows Firewall section of the control panel, it
> asks
> me to start the Internet Connection Sharing service and Im reluctant as Im
> not sure if this will block me out of Terminal Services.
>
> Can anyone tell me if I start this service, will I have a chance to add
> exceptions before the firewall starts? So that I can add a terminal
> services
> exception to allow me to manage the server remotely without having to make
> a
> call to the ISP while the server is down.
>
> Thank you,
> Jason



Similar ThreadsPosted
Windows 2003 server disaster re: firewall and RRA December 8, 2006, 8:24 am
Enabling Some Others Language in Windows 2003 Lite Version (Or XP Lite) May 9, 2006, 2:23 am
Enabling all Subject RDNs in MS CA 2003 September 7, 2005, 3:19 am
Can not use UNC path in Windows server 2003 server 64 bit OS September 30, 2005, 4:19 pm
Windows 2003 Firewall & FTP December 6, 2006, 3:31 pm
Windows Update fails on Windows 2003 server June 23, 2005, 7:27 pm
Windows 2003 -Configure Firewall- September 9, 2005, 4:53 am
RE: WIndows Server 2003 July 29, 2005, 12:16 am
Windows 2003 server SP1 September 16, 2005, 12:06 am
Editing Windows firewall ruleset for 2003 Std ? August 18, 2005, 11:41 am

The site map in XML format XML site map

Contact Us | Privacy Policy