Windows 10: GPO - Firewall Loggin

Discus and support GPO - Firewall Loggin in AntiVirus, Firewalls and System Security to solve the problem; I'm configuring the Windows Defender Firewall with Advanced Security Log via GPO and the setting that I applied are the following: LogFileName:... Discussion in 'AntiVirus, Firewalls and System Security' started by {}Panda{}, Nov 25, 2020.

  1. {}Panda{} Win User

    GPO - Firewall Loggin


    I'm configuring the Windows Defender Firewall with Advanced Security Log via GPO and the setting that I applied are the following:


    LogFileName: %systemdrive%\test\Info\pfirewall.log

    LogAllowed: Yes

    LogBlocked: Yes

    LogMaxSizeKilobytes: 16,385


    When I check wf.msc on the remote device the settings are OK and grey-out.

    But when I issue the "Get-NetFirewallProfile" powershell command the configuration is different.
    The two screenshot are from the same machine.


    GPO - Firewall Loggin 230331f1-aad4-4578-adf9-01c3dc80096f?upload=true.jpg


    After issuing the command manually "Set-NetFirewallProfile -Profile Domain -LogFileName "%SystemDrive%\test\Info\pfirewall.log" -LogAllowed True -LogBlocked True -LogMaxSizeKilobytes 16385" the configuration finally applied.


    There seem to be something blocking the configuration from applying.


    The endpoint is a Windows 10 1909

    The DC is a 2012 R2


    I'm I doing something wrong? Maybe I skipped a step. How do you guys do it?

    :)
     
    {}Panda{}, Nov 25, 2020
    #1

  2. Windows 10 - Security Center - How to turn off Firewall notification with gpo or script

    Hi Simon,



    Thank you for posting the query on Microsoft Community. I am sorry to know that you are facing issues with Windows 10.



    Please follow the steps below, to disable the Firewall notification with GPO:




    • Type Group Policy in the search bar.

    • Select Edit Group Policy.

    • Under the section Computer configuration, expand
      Windows settings
      .

    • Expand Security Settings.

    • Expand Windows firewall with advanced security.

    • Right click on Windows firewall with advanced security
      and select Properties.

    • Click on the drop down option of all three Firewall State, Inbound connections and outbound Connections and set to off.


    In future, if you have any issues related to Windows, do get back to us. We will be happy to assist you.
     
    Syed Abdul Jabbar, Nov 25, 2020
    #2
  3. cosmos Win User
    Enabling Network Discovery via GPO does not work when Windows Firewall


    Environment: Windows domain

    I'm trying to turn on network discovery for 100+ computers and I've created a computer-targeted GPO following instructions from this article: https://www.technig.com/enable-netwo...-group-policy/

    I create a test OU and put one computer in said OU and apply GPO to the computer. I then run gpupdate /force on the targeted machine and restart the computer. I then run gpresult /scope computer /v and confirm that the GPO is being applied.

    Incidentally, I didn't do the second part that's required for this to work, which is turn on Windows Firewall via GPO as per the article, but just to test I ran the GPO and confirmed that Network Discovery is turned on only when I turn off Windows Firewall manually when I check Advanced sharing settings: https://i.imgur.com/E7y9OBn.png
    When I turn Windows Firewall back on, network discovery and file sharing turn off as per screenshot: https://i.imgur.com/UlJvX5E.png

    So I know that my GPO is turning on Network Discovery but windows firewall is blocking it, at least when some inbound rules aren't made yet. I can't turn off Windows Firewall completely (yet) so I proceed to include Windows Firewall exceptions into my GPO as per article instructions. Note that the article suggests only to include inbound rules and not outbound.

    I then include these Windows Firewall rules as a part of my network discovery GPO (I didn't bother to create a separate GPO--don't know if this might be a problem).

    Anyway, I apply this GPO and I see that the computer pulls it down. The problem is with these inbound firewall rules applied both network discovery and file and print sharing and still turned off. And when I look at Windows Firewall inbound rules I see that the rules are applied and enabled but the tick box for network discovery won't turn on. When I turn off windows firewall for domain the tick box shows it's enabled. So windows firewall is preventing this from working and I don't know what rules to enable to make it work. Turning off windows firewall is the only solution but it's too global.

    What am I doing wrong here? Should I have set GPO to enable firewall rule first and then set GPO for enabling network discovery a period after? In my "Network Discovery GPO" I have both network discovery and firewall rules both set. Should I split them up?

    I appreciate any insight on this. I really need to get this to work. Thank you.
     
    cosmos, Nov 25, 2020
    #3
  4. GPO - Firewall Loggin

    Good Antivirus + Firewall

    I would never put anything Norton on my computer.

    Nod32 is arguably the best antivirus. AVG is likely not as good, but it's free and at least pretty good.

    Firewalls, I'd put Comodo and whatever "Tiny Personal Firewall" is named nowadays on your short list. I think Kerio might have sold it now and it's named something else. Otherwise, just put Comodo on your short list. I think the current version's ease of use has taken a step backwards, seems a bit counter-intuitive when trying to do certain things with it, but overall it does a good job and the price is right.
     
    Deusxmachina, Nov 25, 2020
    #4
Thema:

GPO - Firewall Loggin

Loading...
  1. GPO - Firewall Loggin - Similar Threads - GPO Firewall Loggin

  2. Loggin into a admin account.

    in Windows 10 Gaming
    Loggin into a admin account.: Hello, I recently bought a PC from a friend, and I believe I deleted his account on this pc without changing over the admin access to my account, so I am stuck on a local and standard account and as a result the computer won't let me download/change any setting obviously...
  3. Loggin into a admin account.

    in Windows 10 Software and Apps
    Loggin into a admin account.: Hello, I recently bought a PC from a friend, and I believe I deleted his account on this pc without changing over the admin access to my account, so I am stuck on a local and standard account and as a result the computer won't let me download/change any setting obviously...
  4. Loggin into a admin account.

    in Windows 10 Customization
    Loggin into a admin account.: Hello, I recently bought a PC from a friend, and I believe I deleted his account on this pc without changing over the admin access to my account, so I am stuck on a local and standard account and as a result the computer won't let me download/change any setting obviously...
  5. Windows Firewall with polices from a GPO - Stay persistent with firewall disabled

    in Windows 10 Gaming
    Windows Firewall with polices from a GPO - Stay persistent with firewall disabled: Since the 1st of February, we have observed a new behaviour within an On-Prem AD and Windows 10. After Patch Tuesday 31st Jan.For any GPO defined with setting:Computer Configuration/Policies/Windows settings/Security Settings/Windows Defender Firewall with Advanced...
  6. Windows Firewall with polices from a GPO - Stay persistent with firewall disabled

    in Windows 10 Software and Apps
    Windows Firewall with polices from a GPO - Stay persistent with firewall disabled: Since the 1st of February, we have observed a new behaviour within an On-Prem AD and Windows 10. After Patch Tuesday 31st Jan.For any GPO defined with setting:Computer Configuration/Policies/Windows settings/Security Settings/Windows Defender Firewall with Advanced...
  7. Windows Firewall with polices from a GPO - Stay persistent with firewall disabled

    in AntiVirus, Firewalls and System Security
    Windows Firewall with polices from a GPO - Stay persistent with firewall disabled: Since the 1st of February, we have observed a new behaviour within an On-Prem AD and Windows 10. After Patch Tuesday 31st Jan.For any GPO defined with setting:Computer Configuration/Policies/Windows settings/Security Settings/Windows Defender Firewall with Advanced...
  8. Unable to use loggin profile

    in Windows 10 Network and Sharing
    Unable to use loggin profile: I have an issue with one of my loggin profiles on my laptop where if I log in, it won't sign into my actual account and comes up with this:As you may also see, everything has returned to default. This is because it has created a "TEMP" user account while I'm logged in. All my...
  9. Authentificator notification on loggin

    in AntiVirus, Firewalls and System Security
    Authentificator notification on loggin: Hi, I would like to know if it's possible to get a notification on Microsoft Authentificator (on android) each time my Microsoft account or Windows computer is logged in....
  10. GPO

    in Windows 10 Drivers and Hardware
    GPO: So i applied GPO to block removable devices and as a result one of our employees can't access to his internal HDD, his getting "Access Denied". He has windows 10 OS/ Non of our other employees have experienced this problem. Please help....