eG Monitoring
 

Measures reported by WinFirewallTest

If the Windows firewall rules of the Active Directory server are changed – i.e., are added, modified, or removed – it can impact accesses to and from the server. This is why, it is important that such critical changes are tracked and vetted. For this purpose, administrators can take the help of the WinFirewallTest test. This test brings Windows Firewall configuration changes to the immediate notice of administrators, reports what has changed, and also reveals who made the change. This enables administrators to rapidly isolate unauthorized / unnecessary changes. In addition, the test also captures and reports firewall rules that failed to load the group policy, so that administrators can troubleshoot the failure.

Output of the test : One set of results for every Active Directory that is being monitored

The measures made by this test are as follows:

Measurement Description Measurement Unit Interpretation
firewallRuleAdded Indicates the number of firewall rules that were added during the last measurement period. Number The detailed diagnosis of this measure reveals the firewall rules that were added and the user who added them.
firewallRuleChanged Indicates the number of firewall rules that were changed during the last measurement period. Number The detailed diagnosis of this measure reveals the firewall rules that were changed and who changed them.
firewallRuleDeleted Indicates the number of firewall rules that were deleted during the last measurement period. Number The detailed diagnosis of this measure reveals the firewall rules that were deleted and the user who deleted them.
firewallRuleFailed Indicates the number of firewall rules that failed to load the group policy during the last measurement period. Number The detailed diagnosis of this measure reveals the firewall rules that failed to load the group policy.