๐๐ฒ๐ณ๐ฎ๐๐น๐ โ ๐๐ฎ๐ฟ๐ฑ๐ฒ๐ป๐ฒ๐ฑ
Real configs. Real fixes. Windows & AD security.
๐ฃ๐น๐ฒ๐ฎ๐๐ฒ, ๐ฑ๐ผ๐ปโ๐ ๐๐๐ฟ๐ป ๐๐ผ๐๐ฟ ๐ณ๐ถ๐ฟ๐ฒ๐๐ฎ๐น๐น ๐ผ๐ณ๐ณโฆ
It might sound surprising, but I still see this way too often:
โ ๏ธ Windows Firewall completely disabled for no real reason.
Sometimes it almost feels like the deployment process is:
โก๏ธ Install Windows Server โก๏ธ sign in โก๏ธ disable Windows Firewall
I always ask ๐๐ต๐, and the answer is usually some ๐ผ๐น๐ฑ ๐ฏ๐ฎ๐ฑ ๐ฒ๐ ๐ฝ๐ฒ๐ฟ๐ถ๐ฒ๐ป๐ฐ๐ฒ. Something did not work years ago, the firewall was blamed, and since then it has simply been disabled everywhere.
โ That is a ๐ต๐๐ด๐ฒ ๐บ๐ถ๐๐๐ฎ๐ธ๐ฒ.
Even with good network segmentation, Windows Firewall can still protect devices inside the same network segment after an attacker gets in. Without host-level filtering, ๐น๐ฎ๐๐ฒ๐ฟ๐ฎ๐น ๐บ๐ผ๐๐ฒ๐บ๐ฒ๐ป๐ between systems becomes much easier.
โ At the very least, ๐ฒ๐ป๐ณ๐ผ๐ฟ๐ฐ๐ฒ the enabled state through Group Policy.
๐น From there, ๐ฑ๐ฒ๐ณ๐ถ๐ป๐ฒ ๐ฟ๐๐น๐ฒ๐ for each group of devices based on what they actually need.
๐น Once you have central rule management in place, you can also decide whether ๐น๐ผ๐ฐ๐ฎ๐น๐น๐ ๐ฐ๐ฟ๐ฒ๐ฎ๐๐ฒ๐ฑ ๐ณ๐ถ๐ฟ๐ฒ๐๐ฎ๐น๐น ๐ฟ๐๐น๐ฒ๐ should be allowed or ignored.
And Windows Firewall can do much more than simply allow or block ports. Once you understand it properly, it becomes a very powerful security control.
I remember an excellent article from Michael Waterman about using Windows Firewall to create something like ๐ฐ๐ผ๐ป๐ฑ๐ถ๐๐ถ๐ผ๐ป๐ฎ๐น ๐ฎ๐ฐ๐ฐ๐ฒ๐๐.
โ ๏ธ And even if you use another firewall product, or Windows Firewall is managed through another platform, please review the resulting rules.
โก๏ธ More than once, I have found an ๐ฎ๐น๐น๐ผ๐ ๐ฎ๐ป๐ / ๐ฎ๐ป๐ rule at the end of the list…
๐๐ณ ๐๐ผ๐ ๐๐ฎ๐ธ๐ฒ ๐ผ๐ป๐น๐ ๐ผ๐ป๐ฒ ๐๐ต๐ถ๐ป๐ด ๐ณ๐ฟ๐ผ๐บ ๐๐ต๐ถ๐ ๐ฝ๐ผ๐๐:
โ Please, do not turn it off.
If you are interested in securing Windows infrastructure properly, I created a condensed course called ๐ช๐ถ๐ป๐ฑ๐ผ๐๐ ๐๐ป๐ณ๐ฟ๐ฎ๐๐๐ฟ๐๐ฐ๐๐๐ฟ๐ฒ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐. It is available online, and free previews are available so you can check the content first.
Do you centrally manage Windows Firewall in your environment, or is it still handled differently on every server?
