Sure, I can be more specific. My desktop support technician is managing a public access computer lab. We currently have 4 XPSP2 computer on that network with their firewalls turned off. The DS Tech began the process of reinstalling one of the existing W2K PCs to XPSP2. After the reinstallation he set the firewall setting to OFF via our administrative user account.

I had assumed this would set the firewall for all users logging onto the system, but my DS tech is telling me that's not the case. I wanted to verify with "the think tank" before persuing the subject further.

I have installed the XPSP2 ADM templates on my Win2000 GPO for making this modification centrally, but for some reason, on this domain, the template isn't populating the GPO with the proper options for Network Connections, which includes the mods for the XP Firewall.

I'm hoping it's just a slow AD replication issue, but it may go deeper. I have another network I manage where this GPO works just fine.

One interesting thing to note is that in the GPO for modifying the Firewall there are two Profile types: Domain and Standard. Intuitively, I assume this is the difference between a domain user and a local user.... (Anyone have any insight)

_________________________
let the wise listen and add to their learning,
and let the discerning get guidance- Proverbs 1:5