The Windows XP SP2 Firewall - PowerPoint PPT Presentation

1 / 10
About This Presentation
Title:

The Windows XP SP2 Firewall

Description:

... Windows Firewall Settings for Microsoft Windows XP with Service Pack 2' http: ... to Functionality in Microsoft Windows XP Service Pack 2' http://go.microsoft.com ... – PowerPoint PPT presentation

Number of Views:43
Avg rating:3.0/5.0
Slides: 11
Provided by: kenho1
Category:
Tags: firewall | sp2 | windows

less

Transcript and Presenter's Notes

Title: The Windows XP SP2 Firewall


1
The Windows XP SP2 Firewall
  • ITS Information Security Office
  • Windows Sysadmin Meeting
  • February 3, 2005
  • Ken HooverSr. Systems Programmer
  • ken.hoover_at_yale.edu

2
Agenda
  • The XP Firewall SP1 vs. SP2.
  • More details
  • Configuring the firewall with Group Policy
  • The Exceptions Control panel
  • Firewall Pop-ups Making the right call
  • Application vs. Port Exceptions
  • An Announcement

3
The XP Firewall SP1 vs SP2
Service Pack 1
Service Pack 2
  • Firewall on by default
  • Active before computer goes on network
  • Active for all network connections
  • Exceptions may be limited in scope
  • New no exceptions operational mode
  • ICF Must be enabled
  • Starts after network stack is up.
  • Configured separately for each interface
  • Simple exceptions

4
More Information
  • The Windows Firewall is stateful.
  • Can be completely managed from command line or
    through group policy.
  • Domain vs. Non-Domain firewall Group Policy
    settings
  • Firewall can log information on dropped and/or
    accepted packets
  • XP SP2 Firewall improvements are being ported to
    Windows Server 2003 in Service Pack 1 (out soon)

Various SP2 gotchas listed atbabs.its.yale.edu
/yalead/sp2notes.aspsubmit your favorites.
5
Group Policy Settings
6
Firewall Exceptions
Configured with group policy
7
Making the Right Call
8
More on Application vs. Port Exceptions
  • Both kinds may be used in combination
  • Port Exceptions
  • Allow traffic to a particular port.
  • Application Exceptions
  • Allow an application to open any ports that it
    wants.
  • Useful for well-known apps so users dont get
    pop-ups (use group policy to deploy in advance)
  • Specify path of the executable that will be
    listening.
  • Can be deployed in advance.
  • BE AWARE
  • Applications that are given an application
    exception are allowed to open any ports they
    want even if the port is blocked by a port
    exception.

9
Questions?
  • Deploying Windows Firewall Settings for
    Microsoft Windows XP with Service Pack 2
    http//go.microsoft.com/fwlink/?LinkId23277
  • Changes to Functionality in Microsoft Windows
    XP Service Pack 2 http//go.microsoft.com/fwlink/
    ?LinkId28022

10
ANNOUNCEMENT
  • Lunchtime Windows Roundtable meetings will
    begin Feb 23rd and repeat every other month at
    221 WhitneyCurrently Scheduled Feb 23, April
    20, June 22, Aug 24, and Oct 26
  • Public List windows-roundtable_at_panlists.yale.edu
  • See www.yale.edu/yalead for details.
  • These meetings will alternate with security
    meetings for both the Windows and the unix
    community.See www.yale.edu/its/security/sysadmin.
    htm for more on the security meetings.
Write a Comment
User Comments (0)
About PowerShow.com