A new era - WinXP SP2 firewall reveals

  
Windows Firewall is an updated version of the original Internet Connection Firewall in Windows XP Service Pack 2. By default, the firewall is open on all NIC interfaces. Whether it is a new installation or upgrade of Windows xp Installation, this option provides more protection for network connections by default. However, if some applications are not working in this firewall filtering state, they will not be compatible with this new operating system.

Update the user interface and new features



To configure the Windows Firewall, you can open it from the Security Center, the Security Center is located in the Control Panel, of course, you can also directly Open the Windows Firewall console in the Control Panel and there is a third option to access the Firewall Console from the Advanced tab of the Network Connection. There are 3 options in the main tab:

Enabled (Recommended)

Exceptions not allowed

Off (not recommended)

You have chosen not to allow exceptions, and Windows Firewall will block all network requests that connect to your computer, including the applications and system services listed in the Exceptions tab. In addition, the firewall will also intercept file and printer sharing, as well as network device detection. Using a Windows Firewall that does not allow exceptions is more appropriate for connecting to a personal computer on a public network, such as a computer that is commonly used at hotels and airports. Even if you use the Windows Firewall with the Exceptions option, you can still browse the web, send an email, or even use communications software.




Exceptions tab allows you to add a block rule exceptions for programs and ports to allow specific inbound traffic. For each exception, you can set a scope accordingly. For the home and small 旃矣 纾 纾 纾 錾 錾 錾 錾 錾 錾 錾 錾 錾 錾 錾 錾 赝纭 赝纭 允 允 允 允 允 允 允 允 允 允In this way, only network requests from a specific range of IP addresses can be accepted.

There is also a button to add a program in the Exceptions tab. If you want other clients on the network (outside the firewall) to be able to access a particular program or service on your local machine, and you don't know which port and which type of port the service or service will use, in this case You can add this program or service to the Windows Firewall exception to ensure it is accessible externally.




The following settings can be configured in the Advanced tab:

Application-specific rules for each web interface
< BR> Security Record Configuration

Global ICMP Rules, Control Messages via the Internet Protocol
(ICMP) allows computers on the network to share and communicate error and status information.

By default, all Windows Firewall settings can be restored to their default state

We can configure different rules for different network connections. Combining the settings in the Exceptions with the additional settings for the network connection in the Advanced Options is called the Windows Firewall "resultant set".

Group Policy Configuration

By using Windows Firewall, administrators can make the necessary protection for a public connection to a small network or a separate computer connected to the Internet. They provide security protection by deploying the appropriate configuration settings for the Windows Firewall on the network and launching it. Windows Firewall Group Policy configuration can be found in the following location of the Group Policy console:

Computer Configuration/Administrative Templates/Network/Network Connections/Windows Firewall

Computer Configuration/Administrative Templates/Network/Network Connections/Windows Firewall/Domain Profile

Computer Configuration/Administrative Templates/Network/Network Connections/Windows Firewall/Standard profile

In Windows XP SP2, Windows Firewall is set to block all ports by default. This also means that the server-to-client application will not be able to reach the client. In this case, the IPSEC can be set in the group policy to verify and trust the request sent by the server-side application to the client. The Group Policy setting of "Windows Firewall: Allow authenticated IPSEC bypass" allows you to specify whether IPSEC authentication for Windows Firewall is enabled to allow proactive incoming messages from the specified system.

command-line tool




Windows Firewall configuration and status information can be obtained via the command line Netsh.exe. We can use the netsh firewall command to get firewall information and modify firewall settings.

Commands in this context:

--------------------------------- ----------------------

? - Displays a list of commands.

add - Adds firewall configuration.

delete - Deletes firewall configuration.

dump - Displays a configuration script.

help - Displays a list of commands.

reset - Resets firewall configuration to default .

set - Sets firewall configuration

show -.. Shows firewall configuration
safety warnings




in Windows In XP SP2, when a user runs an application locally and will serve as an Internet server, Windows Firewall will pop up a new security warning dialog (above). You can add this application or service to the Windows Firewall exception using the options in the dialog. The exception configuration of the Windows Firewall allows for specific inbound connections. If the program does not work properly after using this method, you can isolate the problem by the following analysis steps:

Add the program to the exception;

Add the port to the exception;

Use firewall security record;

Disable firewall (not recommended).

Copyright © Windows knowledge All Rights Reserved