S
Scott Herriman
I have a question regarding the MSDN help for Windows XP SP2 on the page,
"Firewall - Developer Implications" in the section entitled "IPv4 inbound
connections for services"
http://msdn.microsoft.com/security/productinfo/XPSP2/networkprotection/firewall_devimp.aspx
The paragrah in question reads (see link for more context):
"If the user does not consent, then the service should still use the
INetFwV4OpenPort COM interface to add rules to Windows Firewall to open the
fixed port or ports needed by the service. These rules, however, should not
be enabled so that an administrator can easily turn the rules on if
necessary at a later time."
I do not understand the last sentence? Can some one clarify what they mean.
Is this the same sentiment as found under the heading "IPv4 Inbound
Connections for Services" on another page?
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnwxp/html/securityinxpsp2.asp
I think that on the second page they are more clear when they say:
"If the user does not consent, then the service should still use the
INetFwV4OpenPort API to add rules to ICF to open the fixed port or ports
needed by the service. However, these rules should not be enabled. "
Sorry for the cross post I think that it should be on topic for the most
part. I am hoping that one of MS guys will read this and see if they can
clearup the confusion on the page in question.
Thanks,
Scott
"Firewall - Developer Implications" in the section entitled "IPv4 inbound
connections for services"
http://msdn.microsoft.com/security/productinfo/XPSP2/networkprotection/firewall_devimp.aspx
The paragrah in question reads (see link for more context):
"If the user does not consent, then the service should still use the
INetFwV4OpenPort COM interface to add rules to Windows Firewall to open the
fixed port or ports needed by the service. These rules, however, should not
be enabled so that an administrator can easily turn the rules on if
necessary at a later time."
I do not understand the last sentence? Can some one clarify what they mean.
Is this the same sentiment as found under the heading "IPv4 Inbound
Connections for Services" on another page?
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnwxp/html/securityinxpsp2.asp
I think that on the second page they are more clear when they say:
"If the user does not consent, then the service should still use the
INetFwV4OpenPort API to add rules to ICF to open the fixed port or ports
needed by the service. However, these rules should not be enabled. "
Sorry for the cross post I think that it should be on topic for the most
part. I am hoping that one of MS guys will read this and see if they can
clearup the confusion on the page in question.
Thanks,
Scott