[Dshield] Windoze Questions...

John Holmblad jholmblad at aol.com
Sun Feb 15 19:05:11 GMT 2004


in case you are not aware, the Windows XP/2003 Internet Connection 
Firewall (ICF) can be configured to open up additional protocol/port 
combinations. I have used this configurability aspect of the ICF to 
enable it to work on simple workgoup (non-AD domain) LANS. This despite 
Microsoft's generic recommendation to leave the ICF off  for computers 
inside the firewall and on the Microsoft LAN.  I have not yet fiddled 
with the ICF to get it to work on an AD domain based LAN but  I believe 
that can be done also, especially for the non-server computers, whose 
range of protocol/port requirements is typically more limited than that 
of Windows server computers.

