Jump to content

Windows 10 Defender Firewall Rant

Graham Carter

windows_firewall_vista_icon.png.a574aba429777bacc8cedd7baea5618f.pngWindows Defender firewall doesn't follow logic!!!!!

 

Configured a nice shiny new Dell lappy for a customer earlier today, ran all of the updates, joined it to the domain etc etc

 

thumb_126299_default_td_128x128.png.56a139173b6a6c5369e5a0c98506b5f9.png

 

Network connectivity - CHECK

Showing and enabled in active directory - CHECK

Can browse network shares - CHECK

IPCONFIG query - CHECK

 

fail.gif.7f48d048eee6b621db2bb6cc1d323098.gif

 

PING DNS name from another pc - FAIL

PING IP address from another pc - FAIL

RDP DNS / IP from another pc - FAIL

Rebooted laptop several times - FAIL

Disabled the windows defender firewall - FAIL

 

What eventually worked was...

Windows firewall > "Allow app or feature through windows firewall" > check the box "File and Printer" to enable

 

The reason for the rant was to state why the frig was Ping / RDP / File Sharing blocked even with the flipping defender firewall was turned off! talktothehand.gif.5659f78dc2e362dfafce13fbc234138a.gif

asdf.gif.32d23cd206766c5a11d7020014d78cc0.gifjihad_emoticon.gif.7f4dae563be978e1d911d02babc32c73.gifo.gif.c4e79effe56fd2a24e3d1d711a0aba54.gifpfft.gif.06581486e4f0a8cdcfe5d1dc37aa43e5.gif mob.gif.386b100be7b138eefc5450e8da6adf77.gif

 

Link to comment
Share on other sites

Link to post
Share on other sites

You'll get even more funny moments as soon as you/or some admin configures Windows Firewall rulesets with GPO. Then you sit at a customers endpoint, change Firewall Rulesets and they just don't work. They get shown, listed at active but don't get applied due to to Domain GPO Rulesets which totally disable local rulesets.

 

 

Main System:

Anghammarad : Asrock Taichi x570, AMD Ryzen 7 5800X @4900 MHz. 32 GB DDR4 3600, some NVME SSDs, Gainward Phoenix RTX 3070TI

 

System 2 "Igluna" AsRock Fatal1ty Z77 Pro, Core I5 3570k @4300, 16 GB Ram DDR3 2133, some SSD, and a 2 TB HDD each, Gainward Phantom 760GTX.

System 3 "Inskah" AsRock Fatal1ty Z77 Pro, Core I5 3570k @4300, 16 GB Ram DDR3 2133, some SSD, and a 2 TB HDD each, Gainward Phantom 760GTX.

 

On the Road: Acer Aspire 5 Model A515-51G-54FD, Intel Core i5 7200U, 8 GB DDR4 Ram, 120 GB SSD, 1 TB SSD, Intel CPU GFX and Nvidia MX 150, Full HD IPS display

 

Media System "Vio": Aorus Elite AX V2, Ryzen 7 5700X, 64 GB Ram DDR4 3200 Mushkin, 1 275 GB Crucial MX SSD, 1 tb Crucial MX500 SSD. IBM 5015 Megaraid, 4 Seagate Ironwolf 4TB HDD in raid 5, 4 WD RED 4 tb in another Raid 5, Gainward Phoenix GTX 1060

 

(Abit Fatal1ty FP9 IN SLI, C2Duo E8400, 6 GB Ram DDR2 800, far too less diskspace, Gainward Phantom 560 GTX broken need fixing)

 

Nostalgia: Amiga 1200, Tower Build, CPU/FPU/MMU 68EC020, 68030, 68882 @50 Mhz, 10 MByte ram (2 MB Chip, 8 MB Fast), Fast SCSI II, 2 CDRoms, 2 1 GB SCSI II IBM Harddrives, 512 MB Quantum Lightning HDD, self soldered Sync changer to attach VGA displays, WLAN

Link to comment
Share on other sites

Link to post
Share on other sites

What I hate is by default with a fresh install you have to enable allowing the PC to be discoverable just to ping the interface. Heaven forbid you forget to enable it you're bang your head against the wall down the road wondering why you cant ping the NIC from another computer.

 

Like jeez, I'm not even trying to get in I just want to know if I can talk to you. Why does this have to be so hard?

Link to comment
Share on other sites

Link to post
Share on other sites

Good points so far!  It also raises another question... why do MS even bother having a software firewall built into the OS anymore?

Fair enough, back in the day when people used to connect with modems and what not, you would need some kind of protection against online punks... but nowadays, ALL mainstream routers have in-built firewalls, heck even public WIFI will have firewall protection.

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Graham Carter said:

Good points so far!  It also raises another question... why do MS even bother having a software firewall built into the OS anymore?

Fair enough, back in the day when people used to connect with modems and what not, you would need some kind of protection against online punks... but nowadays, ALL mainstream routers have in-built firewalls, heck even public WIFI will have firewall protection.

Think about all the open WIFI Hotspots at airports, trainstations, coffee shops like Starbucks... there a local firewall really makes sense.

 

 

Main System:

Anghammarad : Asrock Taichi x570, AMD Ryzen 7 5800X @4900 MHz. 32 GB DDR4 3600, some NVME SSDs, Gainward Phoenix RTX 3070TI

 

System 2 "Igluna" AsRock Fatal1ty Z77 Pro, Core I5 3570k @4300, 16 GB Ram DDR3 2133, some SSD, and a 2 TB HDD each, Gainward Phantom 760GTX.

System 3 "Inskah" AsRock Fatal1ty Z77 Pro, Core I5 3570k @4300, 16 GB Ram DDR3 2133, some SSD, and a 2 TB HDD each, Gainward Phantom 760GTX.

 

On the Road: Acer Aspire 5 Model A515-51G-54FD, Intel Core i5 7200U, 8 GB DDR4 Ram, 120 GB SSD, 1 TB SSD, Intel CPU GFX and Nvidia MX 150, Full HD IPS display

 

Media System "Vio": Aorus Elite AX V2, Ryzen 7 5700X, 64 GB Ram DDR4 3200 Mushkin, 1 275 GB Crucial MX SSD, 1 tb Crucial MX500 SSD. IBM 5015 Megaraid, 4 Seagate Ironwolf 4TB HDD in raid 5, 4 WD RED 4 tb in another Raid 5, Gainward Phoenix GTX 1060

 

(Abit Fatal1ty FP9 IN SLI, C2Duo E8400, 6 GB Ram DDR2 800, far too less diskspace, Gainward Phantom 560 GTX broken need fixing)

 

Nostalgia: Amiga 1200, Tower Build, CPU/FPU/MMU 68EC020, 68030, 68882 @50 Mhz, 10 MByte ram (2 MB Chip, 8 MB Fast), Fast SCSI II, 2 CDRoms, 2 1 GB SCSI II IBM Harddrives, 512 MB Quantum Lightning HDD, self soldered Sync changer to attach VGA displays, WLAN

Link to comment
Share on other sites

Link to post
Share on other sites

Furthermore, I really like the Defender Style... Security as part of the system and not drilled in from several angles like 3rd party security, where if errors occur you'll get gray hair or lose your hair all togehter troubleshooting. 

Main System:

Anghammarad : Asrock Taichi x570, AMD Ryzen 7 5800X @4900 MHz. 32 GB DDR4 3600, some NVME SSDs, Gainward Phoenix RTX 3070TI

 

System 2 "Igluna" AsRock Fatal1ty Z77 Pro, Core I5 3570k @4300, 16 GB Ram DDR3 2133, some SSD, and a 2 TB HDD each, Gainward Phantom 760GTX.

System 3 "Inskah" AsRock Fatal1ty Z77 Pro, Core I5 3570k @4300, 16 GB Ram DDR3 2133, some SSD, and a 2 TB HDD each, Gainward Phantom 760GTX.

 

On the Road: Acer Aspire 5 Model A515-51G-54FD, Intel Core i5 7200U, 8 GB DDR4 Ram, 120 GB SSD, 1 TB SSD, Intel CPU GFX and Nvidia MX 150, Full HD IPS display

 

Media System "Vio": Aorus Elite AX V2, Ryzen 7 5700X, 64 GB Ram DDR4 3200 Mushkin, 1 275 GB Crucial MX SSD, 1 tb Crucial MX500 SSD. IBM 5015 Megaraid, 4 Seagate Ironwolf 4TB HDD in raid 5, 4 WD RED 4 tb in another Raid 5, Gainward Phoenix GTX 1060

 

(Abit Fatal1ty FP9 IN SLI, C2Duo E8400, 6 GB Ram DDR2 800, far too less diskspace, Gainward Phantom 560 GTX broken need fixing)

 

Nostalgia: Amiga 1200, Tower Build, CPU/FPU/MMU 68EC020, 68030, 68882 @50 Mhz, 10 MByte ram (2 MB Chip, 8 MB Fast), Fast SCSI II, 2 CDRoms, 2 1 GB SCSI II IBM Harddrives, 512 MB Quantum Lightning HDD, self soldered Sync changer to attach VGA displays, WLAN

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×