VPN and XP Firewall GPO settings

Paul Hutchings <[email protected]>
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
Folks hoping for a little input here:

We have a Juniper SSL VPN that has Network Connect functionality.  We  
have our Group Policies configured so that when onsite XP firewall is  
disabled, when offsite XP firewall is enabled.

It seems what's happening when people use the Network Connect  
functionality of the VPN is that XP is detecting that it has  
connectivity to the LAN and the domain controllers/DNS boxes and is  
switching from the "Standard Profile" to the "Domain Profile" and  
dropping the firewall, which is of course unacceptable (I accept it's  
behaving by design so it's not really a criticism of Microsoft).

What do people do to work around this kind of issue?  I guess a group  
policy for laptops that enables the firewall even when on the domain  
is one option, and I've opened a case with JTAC in case I'm missing  
something on the SA config.

Thanks.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.