Enabling Firewall audit logging in windows

Posted Posted in Server 2008

In this article you can see how to enable audit logging for Windows Firewall with Advanced Security. Windows Firewall with Advanced Security can log firewall activity such as dropped packets or successful connections. By default the firewall log is: %windir%\system32\logfiles\firewall\pfirewall.log You can configure firewall logging by using Group Policy if desired. But what if you want to collect more detailed logging of firewall activity such as kernel mode connections/drops and other filtering activity? You can do this by enabling Windows […]