Event ID 2001 — Firewall Service and Driver Initialization
Applies To: Windows Server 2008 R2
The Windows Firewall service (MpsSvc) and its supporting driver must be running to provide the core firewall functionality and to manage the firewall and connection security rules that define how the firewall operates. When appropriate auditing events are enabled (https://go.microsoft.com/fwlink/?linkid=92666), Windows reports successes and failures in starting the required software components, or when the components stop operating due to a failure.
Note: Because the Windows Firewall services applies Windows service hardening rules to standard Windows Networking services, Microsoft does not support stopping the Windows Firewall service. If you do not want to use Windows Firewall, turn the firewall features off without stopping the service.
|Product:||Windows Operating System|
|Source:||Microsoft-Windows-Windows Firewall with Advanced Security|
|Message:||The following per profile settings were applied by Windows Firewall
%tBlock all Incoming Connections:%t%4
%tUnicast response to multicast broadcast:%t%5
%tLog dropped packets:%t%6
%tLog successful connections:%t%7
%tLog ignored rules:%t%8
%tAllow Local Policy Merge:%t%12
%tAllow Local IPsec Policy Merge:%t%13
%tDefault Outbound Action:%t%14
%tDefault Inbound Action:%t%15
%tMaximum Log file size:%t%17
%tLog File path:%t%18
%tAllow User preferred merge of Authorized Applications:%t%10
%tAllow User preferred merge of Globally open ports:%t%11
This is a normal condition. No further action is required.
Related Management Information
Firewall Service and Driver Initialization