<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:series="http://unfoldingneurons.com/"
		>
<channel>
	<title>Comments on: Windows Server 2008: Windows Firewall with Advanced Security</title>
	<atom:link href="http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/</link>
	<description>For Windows Administrators</description>
	<lastBuildDate>Sun, 21 Mar 2010 23:51:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Sherwin Bidania</title>
		<link>http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/comment-page-1/#comment-138626</link>
		<dc:creator>Sherwin Bidania</dc:creator>
		<pubDate>Sun, 25 Oct 2009 11:48:33 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/#comment-138626</guid>
		<description>What was the resolution on the first comment? im having the same issue right now with my server 2008 DC - firewall wont start.

thanks,</description>
		<content:encoded><![CDATA[<p>What was the resolution on the first comment? im having the same issue right now with my server 2008 DC &#8211; firewall wont start.</p>
<p>thanks,</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Pietroforte</title>
		<link>http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/comment-page-1/#comment-135342</link>
		<dc:creator>Michael Pietroforte</dc:creator>
		<pubDate>Thu, 17 Sep 2009 20:19:53 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/#comment-135342</guid>
		<description>Anushka, this doesn&#039;t sound like a firewall problem because there are no time related settings. You can use a &lt;a href=&quot;http://4sysops.com/archives/free-packet-sniffers-for-windows/&quot; rel=&quot;nofollow&quot;&gt;packet sniffer&lt;/a&gt; to see if the packets come through for this port.</description>
		<content:encoded><![CDATA[<p>Anushka, this doesn&#8217;t sound like a firewall problem because there are no time related settings. You can use a <a href="http://4sysops.com/archives/free-packet-sniffers-for-windows/" rel="nofollow">packet sniffer</a> to see if the packets come through for this port.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anushka</title>
		<link>http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/comment-page-1/#comment-135167</link>
		<dc:creator>Anushka</dc:creator>
		<pubDate>Wed, 16 Sep 2009 06:03:08 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/#comment-135167</guid>
		<description>I have come across a problem where i have configured a rule in the DC to allow incoming traffic for third party program (port 45580) which is installed in the DC.

The problem is that the communication to this program clients stops after around 40 minutes of server uptime. Any clues form the firewalls&#039; point of view?Thanks in advance.</description>
		<content:encoded><![CDATA[<p>I have come across a problem where i have configured a rule in the DC to allow incoming traffic for third party program (port 45580) which is installed in the DC.</p>
<p>The problem is that the communication to this program clients stops after around 40 minutes of server uptime. Any clues form the firewalls&#8217; point of view?Thanks in advance.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/comment-page-1/#comment-82373</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Tue, 01 Jul 2008 17:36:16 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/#comment-82373</guid>
		<description>I understand what you mean now, but I have never tried this. However, I think it should work. It would be very strange if one could configure it, but this doesn’t show an effect. Maybe it has something to do with the programs you used in your test. Maybe they behave differently than you think.</description>
		<content:encoded><![CDATA[<p>I understand what you mean now, but I have never tried this. However, I think it should work. It would be very strange if one could configure it, but this doesn’t show an effect. Maybe it has something to do with the programs you used in your test. Maybe they behave differently than you think.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rotaluclac</title>
		<link>http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/comment-page-1/#comment-80638</link>
		<dc:creator>Rotaluclac</dc:creator>
		<pubDate>Wed, 25 Jun 2008 21:48:48 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/#comment-80638</guid>
		<description>Michael, thanks for your quick response. I understand what you mean, but you do not address the underlying problem (which is probably my fault of not expressing myself clearly enough).

Let&#039;s say there are two programs that send out ICMP Echo Requests. One is ping.exe ; let&#039;s call the other pong.exe . I do trust ping.exe but I don&#039;t trust pong.exe . Can I allow ping.exe to send out ICMP packets, but forbid pong.exe to do the same?

The interface of Vista&#039;s firewall rules suggests that this is possible. The firewall&#039;s behaviour is different. It seems that you may specify a program (first page of the New Rule Wizard), but this program path+filename is only taken into account when the rest of the rule is about TCP or UDP traffic. The specified program seems to be ignored when the rest of the rule is about ICMP traffic.</description>
		<content:encoded><![CDATA[<p>Michael, thanks for your quick response. I understand what you mean, but you do not address the underlying problem (which is probably my fault of not expressing myself clearly enough).</p>
<p>Let&#8217;s say there are two programs that send out ICMP Echo Requests. One is ping.exe ; let&#8217;s call the other pong.exe . I do trust ping.exe but I don&#8217;t trust pong.exe . Can I allow ping.exe to send out ICMP packets, but forbid pong.exe to do the same?</p>
<p>The interface of Vista&#8217;s firewall rules suggests that this is possible. The firewall&#8217;s behaviour is different. It seems that you may specify a program (first page of the New Rule Wizard), but this program path+filename is only taken into account when the rest of the rule is about TCP or UDP traffic. The specified program seems to be ignored when the rest of the rule is about ICMP traffic.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/comment-page-1/#comment-80586</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Wed, 25 Jun 2008 18:00:37 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/#comment-80586</guid>
		<description>Rotaluclac, yes I think it is possible. To allow ping and disallow traceroute you have to block the ICMP type 30. You can configure ICMP types if you click on “customize” when you specify the protocol type (ICMPv4). Check out Wikipedia for the other ICMP types.</description>
		<content:encoded><![CDATA[<p>Rotaluclac, yes I think it is possible. To allow ping and disallow traceroute you have to block the ICMP type 30. You can configure ICMP types if you click on “customize” when you specify the protocol type (ICMPv4). Check out Wikipedia for the other ICMP types.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rotaluclac</title>
		<link>http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/comment-page-1/#comment-80455</link>
		<dc:creator>Rotaluclac</dc:creator>
		<pubDate>Wed, 25 Jun 2008 06:35:04 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/#comment-80455</guid>
		<description>Call it paranoia - I set up the firewall to block all outbound traffic by default, and to allow traffic only if it meets a rule.

I experimented with ping and tracert from the command prompt.

Normally, they both don&#039;t work. When I create a rule to allow outbound ICMP traffic, they do work. That&#039;s what I expect.

Now I change the rule. Instead of allowing ICMP for any program, I change the program to C:\Windows\System32\PING.EXE , and I leave the ICMP part as it was. I expect that ping still works, but tracert doesn&#039;t.

However, neither ping nor tracert works. WHY? To state my question differently: is there a way to allow outbound ICMP for ping, but to disallow it for tracert (or the other way round)?</description>
		<content:encoded><![CDATA[<p>Call it paranoia &#8211; I set up the firewall to block all outbound traffic by default, and to allow traffic only if it meets a rule.</p>
<p>I experimented with ping and tracert from the command prompt.</p>
<p>Normally, they both don&#8217;t work. When I create a rule to allow outbound ICMP traffic, they do work. That&#8217;s what I expect.</p>
<p>Now I change the rule. Instead of allowing ICMP for any program, I change the program to C:\Windows\System32\PING.EXE , and I leave the ICMP part as it was. I expect that ping still works, but tracert doesn&#8217;t.</p>
<p>However, neither ping nor tracert works. WHY? To state my question differently: is there a way to allow outbound ICMP for ping, but to disallow it for tracert (or the other way round)?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The things that are better left unspoken : Remotely managing your Server Core using Compmgmt.msc</title>
		<link>http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/comment-page-1/#comment-59241</link>
		<dc:creator>The things that are better left unspoken : Remotely managing your Server Core using Compmgmt.msc</dc:creator>
		<pubDate>Thu, 03 Apr 2008 09:39:30 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/#comment-59241</guid>
		<description>[...] with the GUI-less Server Core&#160; A few commands to get started with Windows Server Core&#160; Windows Server 2008: Windows Firewall with Advanced Security  Posted: Thursday, April 03, 2008 11:32 AM by Sander Berkouwer Filed under: System Administration, [...]</description>
		<content:encoded><![CDATA[<p>[...] with the GUI-less Server Core&#160; A few commands to get started with Windows Server Core&#160; Windows Server 2008: Windows Firewall with Advanced Security  Posted: Thursday, April 03, 2008 11:32 AM by Sander Berkouwer Filed under: System Administration, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nikola</title>
		<link>http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/comment-page-1/#comment-57735</link>
		<dc:creator>Nikola</dc:creator>
		<pubDate>Tue, 25 Mar 2008 08:05:51 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/archives/windows-server-2008-windows-firewall-with-advanced-security/#comment-57735</guid>
		<description>opk when i try that to do with my server it sends me sam message: An error occurred contacting the firewall. Make sure that the Windows Firewall s
ervice is running and try your request again. 
I even cant start services for firewall. please help me!!!</description>
		<content:encoded><![CDATA[<p>opk when i try that to do with my server it sends me sam message: An error occurred contacting the firewall. Make sure that the Windows Firewall s<br />
ervice is running and try your request again.<br />
I even cant start services for firewall. please help me!!!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
