This can actually be accomplished using existing settings already within group policy. If you navigate to computer settings|Administrative Templates|Network|Network Connections|Windows Firewall, there are two profiles you can make policy changes on. The domain profile is used when the system is connected to your domain, and the standard profile is when the system is not connected to your domain. If you enable the firewall in the standard profile, that should enable the firewall when the laptop is not connected to your network.
Here's a link to a technet article that will help get you started:
http://www.microsoft.com/technet/security/smallbusiness/prodtech/windowsxp/fwgrppol.mspx
Eric


LinkBack URL
About LinkBacks
Reply With Quote