WinSecWiki > Security Settings > Advanced Audit Policies > Object Access > Filtering Platform Packet Drop

Audit Filtering Platform Packet Drop

As the name would indicate, the category logs events associated with packets blocked by Windows Firewall and the lower level Windows Filtering Platform. What's it doing in the higher level Object Access category? Who knows. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.

Coverage on events generated by this category are currently in the Security Log Encyclopedia:

Event ID Title
5152 The Windows Filtering Platform blocked a packet.
5153 A more restrictive Windows Filtering Platform filter has blocked a packet.

Back to top

 

Additional Resources