Icon: Screen-friendly stylesheet Screen-friendly page

CITES Suggested Windows XP Firewall Customizations

Overview

Microsoft Windows XP Service Pack 2 (available through Windows Update) makes several important changes to your computer’s network settings. While these changes will help protect you from harmful viruses and popups, they were not written specifically for the university’s computing needs.

The easiest way to configure the Windows XP Service Pack 2 firewall to CITES specifications is to download and install the two .reg files provided by CITES Security. These files will automatically configure your Service Pack 2 firewall to the specifications found in the next section.

If you are very comfortable making changes to your registry files, you may edit XP SP2 Firewall ICMP - Remote Desktop.reg and XP SP2 Firewall Popup Config.reg by hand. CITES does not recommend manual configuration for non-expert users.

CITES Recommendations

ICMP ­ Remote Desktop:

CITES recommends enabling Remote Desktop (TCP Port 3389) globally. This will allow you to connect to your computer from a remote location, either by computer name or IP address, to administer technical support.

This change also enables ICMP Echo Request (Ping reply), which is useful in preliminary troubleshooting to determine whether you have point to point communication across the network.

Popup Config:

This registry entry modifies the default Service Pack 2 popup blocker settings for Internet Explorer, allowing all popups from the uiuc.edu and uillinois.edu domains to be displayed on your computer.

This change allows Banner, Compass, and other university-hosted websites to function properly.


Other Firewall Configuration Caveats and Recommendations

CITES Security Menu