SP2 deployment using SUS

G

Guest

Hi....

I'm planning to deploy SP2 using SUS and control the firewall settings using
group policy. Because I need to have the ability to manage the client PCs,
I'm going to need to turn off the firewall. I understand that the firewall
will be turned on by default, but if I have a group policy to disable it,
will that disable it or will it be too late because SP2 is already installed
and the firewall is enabled?

If the above method doesn't work, how do I customize the installation so
that the firewall is disabled using SUS as the deployment method?

Thanks so much.
 
O

Oli Restorick [MVP]

Disabling it with a GPO will work just fine. Even with the firewall on,
Group Policy will still work (as the Windows Firewall doesn't block outbound
connections).

Better yet, I'd recommend leaving the standard profile as "on with no
exceptions" and the domain profile as "disabled". I don't know if you've
looked in to the firewall profiles feature, but it's worth using. When
configured that way, when a machine is connected to the company network, the
firewall will be disabled, but when that machine is disconnected from the
network, the firewall will automatically be turned on. This is worthwhile
for laptops, even if you believe that they are
never plugged in to other networks.

If you want to experiment with and test this feature, typing "netsh firewall
show state" from the PC's command line will show you the current firewall
state.

Hope this helps

Oli
 
G

Greg Burns

Do you have any links to "firewall profiles feature". This sounds like what
we need to be doing at my company.

Greg
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top