MSFN Forum: firewall rule time - MSFN Forum

Jump to content


Windows 7 forum rules

If you have questions about customizing Windows 7 that are vLite-specific, please post them in the vLite forum, not here. If you have questions regarding the unattended installation of Windows 7, please post them in the Unattended Windows 7/Server 2008 R2 section.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

firewall rule time

#1 User is offline   vinifera 

  • <°)))><
  • PipPipPipPip
  • Group: Members
  • Posts: 595
  • Joined: 27-August 09
  • OS:Windows 7 x86
  • Country: Country Flag

Posted 05 November 2012 - 07:29 PM

is there a way to see when (date) was certain rule (app blocked or allowed) ?
I don't see in fw settings anything that shows it


#2 User is offline   GrofLuigi 

  • GroupPolicy Tattoo Artist
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1,277
  • Joined: 21-April 05
  • OS:none specified
  • Country: Country Flag

Posted 06 November 2012 - 04:01 PM

In the registry it is the key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules


You can export that key to .txt format with regedit to see the last write time (for the entire key). If you export it to .reg format, on the bottom will be the last created values (but it's not guaranteed).

There are other registry tools that can read and display last write time of keys. I don't know if any of them can do the same for values (but I haven't looked hard). It might be impossible.

RegScanner from Nirsoft can search registry (keys only?) by date.

GL

This post has been edited by GrofLuigi: 06 November 2012 - 04:04 PM


#3 User is offline   vinifera 

  • <°)))><
  • PipPipPipPip
  • Group: Members
  • Posts: 595
  • Joined: 27-August 09
  • OS:Windows 7 x86
  • Country: Country Flag

Posted 06 November 2012 - 08:27 PM

I meant more like
for each rule

as in when was each rule made :P

#4 User is offline   GrofLuigi 

  • GroupPolicy Tattoo Artist
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1,277
  • Joined: 21-April 05
  • OS:none specified
  • Country: Country Flag

Posted 06 November 2012 - 10:30 PM

View Postvinifera, on 06 November 2012 - 08:27 PM, said:

I meant more like
for each rule

as in when was each rule made :P


Yes, I know, but I'm not sure it's possible.

GL

#5 User is offline   vinifera 

  • <°)))><
  • PipPipPipPip
  • Group: Members
  • Posts: 595
  • Joined: 27-August 09
  • OS:Windows 7 x86
  • Country: Country Flag

Posted 08 November 2012 - 07:12 PM

seems it isn't
as firewall doesn't record jack s***

such disapointment...

#6 User is offline   GrofLuigi 

  • GroupPolicy Tattoo Artist
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1,277
  • Joined: 21-April 05
  • OS:none specified
  • Country: Country Flag

Posted 09 November 2012 - 12:17 PM

Now that you mentioned it, there might be something in the firewall log (if you enable it first), but I'm almost sure there will be something in the event log (if you manage to find the event :) ).

GL

#7 User is offline   vinifera 

  • <°)))><
  • PipPipPipPip
  • Group: Members
  • Posts: 595
  • Joined: 27-August 09
  • OS:Windows 7 x86
  • Country: Country Flag

Posted 09 November 2012 - 03:25 PM

well event viewer shows nothing (probably coz it was flushed at some time)
and firewall log doesn't even exist on my PC :(

#8 User is offline   GrofLuigi 

  • GroupPolicy Tattoo Artist
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1,277
  • Joined: 21-April 05
  • OS:none specified
  • Country: Country Flag

Posted 09 November 2012 - 04:01 PM

Well, you need to turn it on http://technet.micro...y/cc742433.aspx

But I think it logs only dropped/passed packets, not creation of rules.

GL

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

2 User(s) are reading this topic
0 members, 2 guests, 0 anonymous users



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2013 msfn.org
Privacy Policy