31 iulie 2012 17:42
Hello, we would like to have an exception GPO to have the local MS FW ISA clients disabled. On that note, is there a specific reg key that controls this behavour.
- Mutat de Rick TanModerator 1 august 2012 01:49 (From:Forefront Client Security)
1 august 2012 04:37
Hi,HKLM\SOFTWARE\Microsoft\Firewall Client\Disable - REG_DWORD "1"
regards Marc Grote aka Jens Baier - www.it-training-grote.de - www.forefront-tmg.de - www.nt-faq.de
1 august 2012 20:16
We don't have the Firewall Client Key under "HKLM\SOFTWARE\Microsoft\"
There is only Firewall Clinet 2004 Key under "HKLM\Software\Wow6432Node\Microsoft\"
I tired to add Disalbe Reg_Dword "1" under that key .. however it didn't work.. :(
2 august 2012 09:27Moderator
Thank you for the post.
“we would like to have an exception GPO to have the local MS FW ISA clients disabled” – what is the purpose of doing that? If you unselect “Enable Forefront TMG Client support for this network” in the TMG server, firewall client will also not work.
Nick Gu - MSFT
2 august 2012 23:48
Thank you for your respond.
We are in the process of re-archtecturing our fw\web proxy system - and as part of that we are setting the pilot group of users to use our new TMG server and would like to have the FW client disalbed for them - automagicaly if possilbe - in order to verify that there are no any issues.
So, if there is a way to do so via Reg Key (exception GPO) that would be great.
Referencing your suggestion, we can potetnally create a few internal sub-networks for our pilot group members and unselect the specific option.
3 august 2012 02:07Moderator
Thank you for the update.
ISA firewall client that works with ISA 2006, will still work with TMG Server. Please refer to the following blog:
Nick Gu - MSFT
- Propus ca răspuns de Nick Gu - MSFTMicrosoft Contingent Staff, Moderator 6 august 2012 01:55
- Marcat ca răspuns de Nick Gu - MSFTMicrosoft Contingent Staff, Moderator 7 august 2012 06:52