Tech Support > Microsoft Windows > Security & Administration > How to prohibit notifications but still log event ID 851 security
How to prohibit notifications but still log event ID 851 security
Posted by csp122 on November 10th, 2005


When the XPSP2 Firewall Policy is set to "Prohibit notifications" it also
appears to not log any indication that an application had any issue with the
firewall configuration. By contrast, with the notifications enabled, an
Event ID 851 message is recorded in the Security log for any application that
encounters an issue with the firewall.

We'd like to roll out SP2 with the firewall enabled to ~500 XP Pro
systems... in doing our research for this deployment, we've created a number
of port & application exceptions, however, we anticipate that some
application will not agree with the firewall. Is there a way to log
application issues, WITHOUT notifying the user with a dialog box?

Thanks.

Posted by Steven L Umbach on November 10th, 2005


Apparently not. If logging is enabled for the Windows Firewall you can use
that also to help track down problems with blocked access by looking for
entries that say dropped,etc. --- Steve


"csp122" <csp122@discussions.microsoft.com> wrote in message
news:066903C9-8844-4C2A-9643-CF01767BDD02@microsoft.com...
> When the XPSP2 Firewall Policy is set to "Prohibit notifications" it also
> appears to not log any indication that an application had any issue with
> the
> firewall configuration. By contrast, with the notifications enabled, an
> Event ID 851 message is recorded in the Security log for any application
> that
> encounters an issue with the firewall.
>
> We'd like to roll out SP2 with the firewall enabled to ~500 XP Pro
> systems... in doing our research for this deployment, we've created a
> number
> of port & application exceptions, however, we anticipate that some
> application will not agree with the firewall. Is there a way to log
> application issues, WITHOUT notifying the user with a dialog box?
>
> Thanks.




Similar Posts