Home page logo

basics logo Security Basics mailing list archives

RE: Windoze GPO Question
From: "Murda Mcloud" <murdamcloud () bigpond com>
Date: Wed, 12 Nov 2008 05:54:41 +1000

Christopher is right on this:
There are the standard and domain profiles for the windows firewall.

-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com]
On Behalf Of Christopher
Sent: Tuesday, November 11, 2008 8:48 AM
To: Jon.Kibler () aset com; security-basics () securityfocus com
Subject: Re: Windoze GPO Question

Computer configuration policies still apply even when you're logging
in locally.  There are some GPO options, however, that will allow you
to specify seperate settings (like firewall, etc.) for when a computer
is on the domain network or when it can't contact the domain
controller, but I don't have them handy.

On 11/10/08, Jon Kibler <Jon.Kibler () aset com> wrote:
Hash: SHA1


This may be slightly off topic, but I have a question about GPO scope.

I have a client that has a bunch of sales people who have laptops. When
they come into their office, they login to the domain. When they are on
the road, they login to 'this computer.'

The problem that the client is seeing has left me scratching my head
about how GP works. What is happening is the client has recently set
some new group policies that do things like specify which name servers
and other network resources a given OU is to use. Now, when these
laptops are taken on the road and the user tries to get Internet
it fails. Why? Because the GPO settings are overriding the DHCP
on 'this computer'.

What I don't understand is why DOMAIN OU GPOs are being applied outside
the scope of the domain. If you are not logging into the domain, why
the domain GPOs in effect? This doesn't make sense. Has my client
somehow misconfigured AD?


Jon Kibler
- --
Jon R. Kibler
Chief Technical Officer
Advanced Systems Engineering Technology, Inc.
Charleston, SC  USA
o: 843-849-8214
c: 843-224-2494
s: 843-564-4224

My PGP Fingerprint is:
BAA2 1F2C 5543 5D25 4636 A392 515C 5045 CF39 4253

Version: GnuPG v1.4.8 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org


Filtered by: TRUSTEM.COM's Email Filtering Service
No Spam. No Viruses. Just Good Clean Email.

Sent from my mobile device

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]