firewall predefined rules missing

Had a thwarted viri attack today.

 

All scans result in joy.

 

But:  the firewall predefined rules missing

 

I have tried what little is advice is available.  Restore defaults, diagnose and repair,...

 

Restore Default Policy results in this error:

Could not restore the default policy.

Error: 3

* Please try a lower page number.

* Please enter only numbers.

* Please try a lower page number.

* Please enter only numbers.

Hi jq85,

 

Thank you for posting in Microsoft Community. As per the description provided the firewalls rules that were pre-defined is missing.

 

Try these steps and check:

Method 1: Run SFC scan on the computer to make sure system files are intact:

How to use the System File Checker tool to troubleshoot missing or corrupted system files on Windows Vista or on Windows 7

http://support.microsoft.com/kb/929833

 

Method 2:

Try to restore Windows Firewall default settings using the command prompt in Administrator mode. 

 

a. Click Start, type cmd.

b. Right click on cmd and select "Run as administrator".

( If this method prompts to enter the administrator password, enter the password and then click ok.)

c. Type this command in the command prompt and hit enter.

    netsh firewall reset

 

Hope this information helps. If you have further questions feel free to reply and we would be glad to assist.

Ravinath P
Forum Moderator - Multiple Forums

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

Did all that before posting.

 

The predefined rules are all missing.

 

I have attempted to import a policy from another w7 comp.  But I get an access denied error.

 

Got any links to where I can get the registry entries to import?

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

I clicked 'Me too' thinking it would add me as having the same problem, but I think it interpreted me as saying my problem is solved.  It isn't.

Been through all the above and got exactly the same as jq85.

Error message importing from a working W7 PC is "Policy import failed.  Error: Access is denied  Code: 5"

Any help would be greatly appreciated.

Andy

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

Having the same issue in my pc (Windows 7 x64).

 

What I found so far:

 

1- Open "Windows Firewall with Advanced Security" window.

1.1- Select "Inbound Rules" on the left.

1.2- Select "New Rule..." action on the right.

1.3- In the "New Inbound Rule Wizard", the Predefined option is grey out.

 

2- Select "Windows Firewall with Advanced Security on Local Computer".

2.1- Select "Restore Default Policy" on the right.

2,2- "Could not restore the default policy. Error : 3".

2.3- Found nothing in the events logs.

 

3- Select "Windows Firewall with Advanced Security on Local Computer".

3.1- Select "Import Policy" on the right.

3.2- Opening a .wfw file from a working windows 7 pc.

3.3- "Policy import failed. Error : Access is denied. Code : 5".

 

4- Cleaned pc with different tools:

4.1- Cleaned pc with "Malwarebytes Anti-Malware".

4.2- Cleaned pc with "Combofix".

4.3- Cleaned pc with "Eset Online Scanner".

 

5- When restarting the pc, the icon for "Microsoft Security Essential" in not showed in the icon tray.

5.1- "Startup" tab of "Msconfig" is showing the following command "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey". Need to start it in startup menu to make it appeared in process list and icon tray.

 

6- Looked permissions in regedit but found nothing unsual for keys containing "Firewall".

 

7- Compared all the "Services" with another Windows 7 pc. No difference.

 

8- Also look the local group policy (gpedit.msc) for this policy: "Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\
System Cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing" = Disabled. Found this in another thread. But not working for me.

 

9- Also tried this command (running as administrator) without success: "C:\Windows\system32>netsh advfirewall reset".

9.1- Returned error: "An unrecoverable Windows Firewall error (0x3) occurred."

 

10- Created a new admin user and tried to turn on network discovery.  No luck.

 

11- The only way I'm able to turn on network discovery is to turn off Windows Firewall.   Once done, Network discovery is turned on automatically.  Also just one inbound rule is automatically added: "Core Networking - Teredo (ICMPv6-In). 

 

12- Also used the "System File Checker" command "sfc /scannow" to troubleshoot missing or corrupted system files.   It reported that some system files were corrupted.  It said that it was unable to repair some of those files and to check c:\windows\logs\CBS\CBS.log for details.  When I look into that file, there is a bunch of very long technical-looking messages, and no clear indication of just which files were repaired successfully and which files were not repaired.

 

13- All "Windows Updates" are installed.

 

14- Also done a "System Restore" but the older "Restore Point" was after I encountered this problem.

 

15- Done a clean boot.  Did nothing.


16- Exported the "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess" registries from a working Windows 7 then imported on the failing Windows 7 =  PARTLY SUCCESSFUL! Now able to communicate with other computers on the local network.  The "Homegroup" is working normally.  Network discovery is activated.  Firewall is ON.  But... there's still issues not fixed.  Points 2 and 3 above are still there.  Sounds like some permissions not set as it should be. 

 

 

Patrick

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

I have had the same issue (the "access is denied" error) when I tried to import the advanced firewall policy from another machine of the same OS.

The Solution was to import this registry branch:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

I have the same problem. Having tried all of the above and only found the copy default policy solution from a naother machine option (which did not work -access denied) I found this.

 

How Do I import this registry branch?

Regards,

Tony

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

I have had the same issue (the "access is denied" error) when I tried to import the advanced firewall policy from another machine of the same OS.

The Solution was to import this registry branch:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess

Thank You Thank You Thank You.

this solved the issue for me.

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

I have had the same issue (the "access is denied" error) when I tried to import the advanced firewall policy from another machine of the same OS.

The Solution was to import this registry branch:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess
Perfect Robert! Many thanks.

This worked on my W8 Enterprise.

But, I don't understand what caused the registry fault after many months of correct work.
Any idea about it?

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

Having the same issue in my pc (Windows 7 x64).

 

What I found so far:

 

2- Select "Windows Firewall with Advanced Security on Local Computer".

2.1- Select "Restore Default Policy" on the right.

2,2- "Could not restore the default policy. Error : 3".

2.3- Found nothing in the events logs.

 

<snip> 


16- Exported the "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess" registries from a working Windows 7 then imported on the failing Windows 7 =  PARTLY SUCCESSFUL! Now able to communicate with other computers on the local network.  The "Homegroup" is working normally.  Network discovery is activated.  Firewall is ON.  But... there's still issues not fixed.  Points 2 and 3 above are still there.  Sounds like some permissions not set as it should be. 

 

 

Patrick

Does this key exist in your system?

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Defaults\FirewallPolicy\FirewallRules

That's where the default rules are stored. If this key is missing you get the symptoms as in (2)
______________________________________________________________________________________________________
Ramesh, Windows Shell MVP 2003-2012.
If this post resolves your issue, pls mark it as an Answer.

Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

For me it was a major virus intrusion that deleted the rules.  And lots of other stuff.

I could not fix it without using restore, which I do not like to do.

I am not happy that a daily restore point is not created automatically.

I am interested in being able to schedule such a task for all my computers and for all my clients' computers. Anybody got a reg entry, or vbs script, that can do this. Something easy to install/configure?

I have spent way much time trying to fix this kind of stuff for my client's, when a recent, daily restore point would have been most useful.

ALL windows computers should come with a predefined scheduled task to create daily restore points.




Was this reply helpful?

Sorry this didn't help.

Great! Thanks for your feedback.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this reply?

Thanks for your feedback.

* Please try a lower page number.

* Please enter only numbers.

* Please try a lower page number.

* Please enter only numbers.

 
 

Question Info


Last updated March 8, 2024 Views 15,833 Applies to: