Skip to content
ShabazTech

Notes of an IT Pro

ShabazTech

Notes of an IT Pro

  • Microsoft Azure
    • Compute
    • Governance
    • Identity
    • Networking
    • Security
    • Storage
  • Microsoft Entra ID
    • Identity
      • Application Management
      • Governance
    • Security
      • Authentication
      • Conditional Access
    • Global Secure Access
      • Internet Access
      • Private Access
  • Microsoft Intune
    • Apps
      • Microsoft365 Apps For Enterprise
    • Devices
      • Windows Clients
    • Monitoring
    • Security
  • Microsoft 365
    • Defender XDR
    • Purview
  • Microsoft OnPrem
    • AD DS
    • Failover Clustering
    • Hyper-V
    • Powershell
    • SQL Server
      • SQL Server 2008R2
      • SQL Server 2012
      • SQL Server 2016
    • System Center Configuration Manager
      • SCCM 2012R2
    • Windows Clients
    • Windows Server
      • Windows Server 2008R2
      • Windows Server 2012
      • Windows Server 2012R2
      • Windows Server 2016
  • Citrix
    • XenApp 6.5
    • XenApp and XenDesktop 7.6 LTSR
    • XenApp and Xendesktop 7.15 LTSR
  • About The Author
  • Microsoft Azure
    • Compute
    • Governance
    • Identity
    • Networking
    • Security
    • Storage
  • Microsoft Entra ID
    • Identity
      • Application Management
      • Governance
    • Security
      • Authentication
      • Conditional Access
    • Global Secure Access
      • Internet Access
      • Private Access
  • Microsoft Intune
    • Apps
      • Microsoft365 Apps For Enterprise
    • Devices
      • Windows Clients
    • Monitoring
    • Security
  • Microsoft 365
    • Defender XDR
    • Purview
  • Microsoft OnPrem
    • AD DS
    • Failover Clustering
    • Hyper-V
    • Powershell
    • SQL Server
      • SQL Server 2008R2
      • SQL Server 2012
      • SQL Server 2016
    • System Center Configuration Manager
      • SCCM 2012R2
    • Windows Clients
    • Windows Server
      • Windows Server 2008R2
      • Windows Server 2012
      • Windows Server 2012R2
      • Windows Server 2016
  • Citrix
    • XenApp 6.5
    • XenApp and XenDesktop 7.6 LTSR
    • XenApp and Xendesktop 7.15 LTSR
  • About The Author
Close

Search

Subscribe
MicrosoftWindows ServerWindows Server 2008R2Windows Server 2012

Configure the Windows Firewall Log

By Shabaz
May 4, 2014 2 Min Read
Comments Off on Configure the Windows Firewall Log

By default logging is disabled for all network profiles in Windows Firewall. So if you want to log dropped packets, or successful connections, you will have to enable logging of these occurrences. You can choose to enable logging locally on a single computer, or you can enable it for several computers, by defining it in a GPO.

Enabling logging can be useful in situations where you are trying to find out why certain type of network communication isn’t working as expected on a server. Personally I always enable logging of dropped packets on all of my servers, and set the maximum log file size to 4MB.

The following procedures apply to Server 2008 R2 and Server 2012.

1. Configuring the Windows Firewall Log on a single computer

1.1 Click Start – Administrative Tools – Windows Firewall with Advanced Security
1.2 Right-click Windows Firewall with Advanced Security on Local Computer → Properties
fwlog1

1.3 On the network profile you want to enable logging, choose Customize in the Logging field.
fwlog2

1.4 Define your options. As you can see default log file path is %systemroot%\system32\LogFiles\Firewall\pfirewall.log
fwlog3

2. Configuring the Windows Firewall Log in a GPO

2.1 In a GPO, browse to the following location

Computer Configuration → Policies → Windows Settings →Security Settings → Windows Firewall with Advanced Security

2.2 Right-click Windows Firewall With Advanced Security – LDAP://…… – Properties
fwlog4

2.3 On the network profile you want to enable logging, choose Customize in the Logging filed.
fwlog5

2.4 Define your options.
fwlog6

As I wrote earlier, by default, you will find the log file at the following location, %systemroot%\system32\LogFiles\Firewall\pfirewall.log
You can open the file and view which packets have been dropped and which have been allowed.
partitioned2

Tags:

MicrosoftServer 2008R2Server 2012Windows Server
Author

Shabaz

Follow Me
Other Articles
Previous

Managing storage with Veritas Storage Foundation for Windows III

Next

Offering Remote Assistance on Windows 7

Archives

Tags

Active Directory Citrix Failover Clustering Microsoft Powershell SCCM SCCM 2012R2 Server 2008R2 Server 2012 Server 2012R2 Server 2016 SQL Server Symantec VSF Test Labs Windows Clients Windows Server XenDesktop 7.6 LTSR Xendesktop 7.15 LTSR

Popular Posts

  • How to check if a machine is physical or virtual
  • Exporting multivalued attributes with Export-CSV cmdlet
  • Installing Remote Desktop License Server on Windows…
  • Configuring Remote Desktop Services Profile settings…
  • Installing Citrix XenApp and XenDesktop 7.15 LTSR
  • Enabling LDAPS with certificate from a 3rd party CA
  • Assigning ownership of files and folders with Takeown.exe
  • Retrieving User properties from Active Directory
  • SCCM 2012 R2 Client Installation
  • Citrix XenApp 6.5 Architectural Components
© 2014- 2026 — ShabazTech. All rights reserved.