Disabling ipv6 changes profile to Domain

create share 646 Reputation points
2021-03-22T01:02:28.193+00:00

Hi,

After I disable ipv6 on my Win 2012 DC, the Windows firewall profile changes from Guest to Domain.

Any Suggestions?

Thanks.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,912 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Dave Patrick 426.1K Reputation points MVP
    2021-03-22T01:06:54.447+00:00

    Domain network profile is correct for domain controller and all domain members. When NLA starts to detect the network location, the machine will contact a domain controller via port 389. If this detection is successful, it will get the domain firewall profile (allowing for correct ports) and we cannot change the network location profile.
    If the domain was not found or process failed, NLA will let you to determine which firewall profile will be used, private or public.

    The Network Location Awareness (NLA) service expects to be able to enumerate the domain’s forest name to choose the right network profile for the connection. The service does this by calling DsGetDcName on the forest root name and issuing an LDAP query on UDP port 389 to a root Domain Controller. The service expects to be able to connect to the PDC in the forest domain to populate the following registry subkey:
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\NetworkList\Nla\Cache\IntranetForests
    If something hinders the DNS name resolution or the connection attempt to the DC, NLA is not able to set the appropriate network profile on the connection.

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments