Computing.Net > Forums > Windows Server 2003 > GPO - Firewall problems

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

GPO - Firewall problems

Reply to Message Icon

Name: MrBedo
Date: September 26, 2006 at 03:57:13 Pacific
OS: XP Pro
CPU/Ram: 3ghz 2gb
Product: dell
Comment:

We have a domain setup with various OUs reflecting the various departments in the company. Policies have been applied to some of these OUs, while some policies sit at the domain level.

One of the domain level GPOs disables the firewall service on Win XP. I need to set it so that this firewall policy does NOT apply to laptop users.

The problem I have is that the laptop users are spread between various OUs and moving their user accounts into a seperate LAPTOP_USER OU is not an option as various different policies affect the various OUs they are already in.

I thought that perhaps if I created a LAPTOP_USERS OU and put their COMPUTER accounts into it (rather than their USER accounts)then applied a seperate policy to it to switch ON the firewall service then this might work. It doesn't seem to though !

I'm fairly new to ADS and policies, so forgive my naivety if I'm missing something obvious, but could anyone recommend a better way to achieve what I want ?

thanks in advance for any help



Sponsored Link
Ads by Google

Response Number 1
Name: dkruger
Date: October 6, 2006 at 08:35:37 Pacific
Reply:

What you suggested you tried about putting the laptop computers into a group policy OU themselves, should work.

Since you are disabling the windows firewall on the domain level policy however, it is likely what is still causing the problem with the firewall not being enabled. You may need to remove that setting from the domain wide policy, and disable it in those that you do not want the firewall running for, and enable for the laptop OU. Hope that helps.


0

Response Number 2
Name: bilbus
Date: October 16, 2006 at 18:32:39 Pacific
Reply:

apply the policy to a group of computers, not domain computers.

make one glocal group "laptops" and "desktops" Add allthe computers into that group. remove the "domain computers" from the apply to section and add just "desktops"

or move the desktops and laptops into their own folder. This way is easier.
I would make a OU "computers" with sub OU's "workstations" and "laptops" and apply policy to the laptops OU


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows Server 2003 Forum Home


Sponsored links

Ads by Google


Results for: GPO - Firewall problems

GPO using which port? www.computing.net/answers/windows-2003/gpo-using-which-port/7673.html

Webserver win20003 www.computing.net/answers/windows-2003/webserver-win20003/2664.html

GPO scripting problems www.computing.net/answers/windows-2003/gpo-scripting-problems/3481.html