Computer/User Node :
MACHINE
Policy Path :
Administrative
Templates\Network\Network Connections\Windows Firewall\Domain Profile
Supported on :
At least Microsoft Windows XP Professional with SP2
Help/Explain Text :
Defines the
set of Internet Control Message Protocol (ICMP) message types that Windows
Firewall allows. Utilities can use ICMP messages to determine the status of
other computers. For example, Ping
uses the echo request message. If you do not enable the Allow inbound echo
request message type, Windows Firewall blocks echo request messages sent by
Ping running on other computers, but it does not block outbound echo request
messages sent by Ping running on this computer. If you enable this policy setting,
you must specify which ICMP message types Windows Firewall allows this computer
to send or receive. If you disable this policy setting, Windows Firewall blocks
all unsolicited incoming ICMP message types and the listed outgoing ICMP
message types. As a result, utilities that use the blocked ICMP messages will
not be able to send those messages to or from this computer. Administrators
cannot use the Windows Firewall component in Control Panel to enable any
message types. If you enable this policy setting and allow certain message
types, then later disable this policy setting, Windows Firewall deletes the
list of message types that you had enabled. If you do not configure this policy
setting, Windows Firewall behaves as if you had disabled it, except that
administrators can use the Windows Firewall component in Control Panel to
enable or disable message types. Note: If any policy setting opens TCP port
445, Windows Firewall allows inbound echo requests, even if the Windows
Firewall: Allow ICMP exceptions policy setting would block them. Policy
settings that can open TCP port 445 include Windows Firewall: Allow file and
printer sharing exception, Windows Firewall: Allow remote administration
exception, and Windows Firewall: Define port exceptions. Note: Other Windows
Firewall policy settings affect only incoming messages, but several of the
options of the Windows Firewall: Allow ICMP exceptions policy setting affect
outgoing communication.
Registry Settings :
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowOutboundDestinationUnreachable,
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowOutboundSourceQuench,
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowRedirect,
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowInboundEchoRequest,
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowInboundRouterRequest,
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowOutboundTimeExceeded,
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowOutboundParameterProblem,
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowInboundTimestampRequest,
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowInboundMaskRequest,
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings!AllowOutboundPacketTooBig
0 التعليقات:
Post a Comment