Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Diabling XP firewall across a LAN/WAN

Status
Not open for further replies.

bubarooni1

Technical User
Dec 18, 2007
51
US
Hi All,

I need to disable the xp sp2 firewall on every machine on my LAN/WAN.

I've seen some scripts to do that on this and other forums, but not every machine I have uses a login script.

As an example, I just found a machine with xxx.xxx.1.10 IP address that didn't show up on my scans because it couldn't be pinged. I discovered it by actually assigning the 1.10 address to a cisco switch which then knocked the user off the network because of the conflict.

Has anyone ever used a 3rd party utility that can accomplish this?

Thanks In Advance
 
it pains me to tell you, but...

NT 4.0 domain spread out across 8 sites, each with it's own class c subnet. all machines use a wins server located at the main site. all remote sites use dhcp off their cisco router.
 
The only problem is if there was a 3rd party tool to disable XP firewalls there would be some serious security issues breached. If I find anything to help, I'll let you know.
 
excellent! i did post it in the other forum too. i'll let you know if they come up with anything there.

thanks again
 
Not sure - the only way I can see doing this is to MAYBE add an importable registry file to a logon script that incorporates the necesssary changes in the registry to disable the Windows firewall. Of course, this requires all your users to have admin access to the local workstations - a hideously horrible idea.

Actually, another way might be to use the PSTOOLS' PSEXEC and remotely execute the registry import on every machine... except that with the firewall enabled, that likely won't work.

So the final question is, why not upgrade to Active Directory Support for NT is dead and it's probably costing you far more in support costs dealing with your NT/XP domain than a AD domain. (This doesn't mean you need to get rid of your NT DCs right away - you can add AD and keep all of them (or almost all of them) online.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top