Firewall Check: Make Profiles Selectable for Evaluation

Summary

The firewall check evaluates all three Windows profiles equally and issues a warning as soon as one is disabled. On domain-joined computers, however, the “Private” and “Public” profiles are regularly disabled without creating a security vulnerability—the domain profile is the only one that applies anyway. The result is warnings that no one can turn off without completely disabling the check. I’d like to be able to choose which profiles are evaluated.

What the check currently offers

Two toggles, both applicable to all profiles:

OptionStandardEffect

Warning if disabled

On

Warning when a profile or zone is disabled

Critical when disabled

off

Critical instead of warning

If a profile is causing issues, my only option is to disable warnOnDisabled for the entire device. This means I also lose the information about the profile that I’m actually interested in.

How this affects my setup

From my test instance, as of today:

DeviceDomainPrivatePublicWhat the check reportsWhat I think

InControl

On

off

off

Warning

Domain profile active, server protected

Admin2012

on</p...

Please authenticate to join the conversation.

Upvoters
Status

In Review

Board
💡

Feature Request

Date

About 1 month ago

Subscribe to request

Get notified by email when there are changes.