Share via

Windows Firewall Logging in wrong profile

Lewis Hardwick 1 Reputation point
2021-10-12T13:10:04.457+00:00

Hi there,

I've rolled out a Group Policy to enable Windows Firewall on a small number of servers. After resolving the permissions issue some people encounter, I'm finding the logging is writing to the wrong files.

I have disabled the ICMP v4 rule so I no longer receive a ping response. I have also configured logging to log dropped packets.

I see 'allow' packets in the domain profile log, but not the drop. When looking in the Public profile log, I see the dropped ICMP packets being logged.

The server is 2019 Standard and domain joined. The workstation I'm pinging from is joined to the same domain, albeit in a different office (Server in Bermuda, workstation in the UK). I'm sure I'm missing something, but I'd expect it to show in the Domain profile logging...

Any ideas?

Thanks!

Windows for business | Windows Server | User experience | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. Limitless Technology 40,106 Reputation points
    2021-10-13T08:38:53.22+00:00

    Hi there,

    Unless the log files have already been created the firewall service actually doesn’t log anything. When setting firewall log file names via GPO you have to manually create the log files. Go into Windows Firewall on each server, go into each profile and click browse next to the file name, then create a log and check if they are login to the right profile.


    If the reply is helpful, please Upvote and Accept it as an answer

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.