简体   繁体   English

Windows 防火墙 GPO 优先级

[英]Windows Firewall GPO Precedence

A recent issue prompted me to question how Windows Firewall applies it's rules when created Locally, and by GPO.最近的一个问题促使我质疑 Windows 防火墙在本地创建和通过 GPO 创建时如何应用它的规则。 I have Windows Server 2012 R2 in which many local firewall rules were created (Via Advanced Firewall, not Local Policy).我有 Windows Server 2012 R2,其中创建了许多本地防火墙规则(通过高级防火墙,而不是本地策略)。 At the same time, I had a few GPOs that would add one-off rules to the system.同时,我有一些 GPO 可以向系统添加一次性规则。 So we have two at play: Local rules created manually (the bulk of the rules) and a few domain-wide rules applied at the OU level.所以我们有两个在起作用:手动创建的本地规则(大部分规则)和一些在 OU 级别应用的域范围规则。

Today (a few months later) I logged in and notice all of the manually created rules are gone, leaving only GPO rules remaining.今天(几个月后)我登录并注意到所有手动创建的规则都消失了,只剩下 GPO 规则。 It's almost like either a Windows Update erased the rules and re-added the generic rules, or perhaps I am misunderstanding how GPOs apply firewall rules.这几乎就像 Windows 更新删除了规则并重新添加了通用规则,或者我可能误解了 GPO 如何应用防火墙规则。 I logged into another server which had similar rule structure, and it too had it's local firewall rules removed.我登录到另一台具有类似规则结构的服务器,它也删除了本地防火墙规则。 I happen to know they all did stick for a good few weeks- and I'm not exactly sure at what point they reverted.我碰巧知道他们都坚持了好几个星期——我不确定他们什么时候恢复了。

My question is, do I need to pick either local firewall rules created manually (or via Local Policy) or go all out with GPO?我的问题是,我需要选择手动(或通过本地策略)创建的本地防火墙规则还是全力以赴使用 GPO? Is a combination of the two not supported?不支持两者的组合吗? Otherwise, what may have reverted all my rules?否则,什么可能会恢复我所有的规则?

It depends on the "Rule merging" settings.这取决于“规则合并”设置。 If rule merging is "Not configured" or "Yes (default)" the Windows firewall will contain both local admin rules and GPO rules.如果规则合并为“未配置”或“是(默认)”,Windows 防火墙将同时包含本地管理规则和 GPO 规则。

You can see the "Rule merging" settings in wf.msc Open wf.msc Right click on "Windows Defender Firewall with Advanced Security" Then properties Finally, under settings click "Customize"您可以在wf.msc中看到“规则合并”设置打开wf.msc右键单击“具有高级安全性的Windows Defender防火墙”然后属性最后,在设置下单击“自定义”

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM