Is there ever a time when Windows XP Firewall be turned off? e.g should it be when the PC/notebook resides within a company domain? Or is it the case that it simply doesn't matter?
Software/Hardware used:
ASKED:
July 24, 2008 7:54 AM
UPDATED:
July 28, 2008 6:34 AM
Thanks for the swift responce. As our company regularly rolls out patches, updates,etc it seems the windows firewall has the effect of blocking the patch from uploading. The only way around this is to turn the firewall off and as updates are rolled out as and when the consensus was to leave the firewall turned off. Would this be considered as bad practice?
Sounds like patch distribution is not working well if the firewall has to be disabled for updates. I would suggest that the IT security group needs to rethink their distribution method and find a more effective way of handing out updates. Microsoft’s WSUS or Systems Center Configuration Manager should not require the firewall to be disabled. The firewall should be configured with the appropriate rules to permit updates from authorized sources.
Are you using a 3rd party security solution along with the windows firewall enabled on the system, if that is the case, the two firewalls are conflicting and hence this issue. Since the function of firewall is well being done by the 3rd party firewall, disabling windows firewall will not hurt any PCs sentiments but enhance the performance and user will not have to encounter abrupt ‘failure of patch update’ messages.