WinSecWiki > Security Settings > Advanced Audit Policies > Policy Change > MPSSVC Rule-Level Policy Change

Audit MPSSVC Rule-Level Policy Change

This chatty category documents the current configuration of the Windows Firewall (aka MPSSVC) whenever it starts as well as any changes to it's configuration. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.

Coverage on events generated by this category are currently in the Security Log Encyclopedia:

Event IDTitle
4944 The following policy was active when the Windows Firewall started.
4945 A rule was listed when the Windows Firewall started.
4946 A change has been made to Windows Firewall exception list. A rule was added.
4947 A change has been made to Windows Firewall exception list. A rule was modified.
4948 A change has been made to Windows Firewall exception list. A rule was deleted.
4949 Windows Firewall settings were restored to the default values.
4950 A Windows Firewall setting has changed.
4951 A rule has been ignored because its major version number was not recognized by Windows Firewall.
4952 Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall.
4954 Windows Firewall Group Policy settings has changed. The new settings have been applied.
4956 Windows Firewall has changed the active profile.
4957 Windows Firewall did not apply the following rule:
4958 Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer:

Back to top

 

Additional Resources