Encontrei a resposta depois de vasculhar a rede e pensei em postar minha pergunta e responder aqui para ajudar os outros. Dave Nickason escreveu :
On any workstation where the firewall is showing as using the non-domain settings, go into Services and set the Network Location Awareness service to start automatically, and then restart the workstation or do gpupdate /force. Setting NLA to automatic startup should fix it permanently. The issue is that with NLA set to manual, it starts too slowly to get the firewall to use the correct (domain) settings.
As far as I know, MS never documented this, but you'll notice that NLA is set to automatic by default in Vista.
Obrigado Dave!