GPO Configurations
Agents that enforce policy require only the Firewall to be enabled with either a local setting or GPO. All other GPO settings should not be set and left as “Not Configured.”
-
To check if a GPO setting is blocking enforcement you can check the C:\Program Files\Cisco Tetra- tion\Logs\TetEnf.exe.log log and search for the following error examples:
-
Rules conflicting with “Preserve Rules=No” setting: “There are firewall rules set in the Group Policy. Secure Workload agent does not have permission to remove these”
-
Firewall set to off: “GPO has disabled firewall for DomainProfile”
-
Default Action is set: “Group Policy has conflicting default inbound action for DomainProfile”
-
To check what GPO policies are being applied to the host, run gpresult.exe /H gpreport.html and open the generated HTML report. In the example below Secure Workload Agent Firewall is applying a Inbound rule which will conflict with Enforcement if “Preserve Rules” is set to “No.”
