É possível ver as alterações feitas no firewall do Windows no passado recente?

10

Gostaria de verificar se algum programa ou porta foi ativado ou desativado nas últimas horas no meu computador no firewall do Windows? Existe algum log onde posso verificar isso?

    
por watbywbarif 16.05.2012 / 13:46

1 resposta

7

The Windows Firewall with Advanced Security operational event logs that can be viewed in Event Viewer. The events in this log show the operational status of Windows Firewall with Advanced Security and changes in its configuration.

Você não precisa ativar o log do Firewall para o visualizador de eventos para capturar esses eventos, o log é para outros fins, como indicado no link "Fonte" abaixo.

Origem

.

Como visualizar os registros de eventos do Firewall

Logs de eventos operacionais no Visualizador de Eventos

.

There are four views of operational events provided:

ConnectionSecurity. This log maintains events that relate to the configuration of IPsec rules and settings. For example, when a connection security rule is added or removed or the settings of IPsec are modified, an event is added here.

ConnectionSecurityVerbose. This log maintains events that relate to the operational state of the IPsec engine. For example, when a connection security rule become active or when crypto sets are added or removed, an event is added here. This log is disabled by default. To enable this log, right-click ConnectionSecurityVerbose, and then click Enable Log.

Firewall. This log maintains events that relate to the configuration of Windows Firewall. For example, when a rule is added, removed, or modified, or when a network interface changes its profile, an event is added here.

FirewallVerbose. This log maintains events that relate to the operational state of the firewall. For example, when a firewall rule become active, or when the settings of a profile are changed, an event is added here. This log is disabled by default. To enable this log, right-click FirewallVerbose, and then click Enable Log.

    
por 16.05.2012 / 15:42