Event ID 4944
The following policy was active when the Windows Firewall startedThe following policy was active when the Windows Firewall started.
Group Policy Applied: %1
Profile Used: %2
Operational mode: %3
Allow Remote Administration: %4
Allow Unicast Responses to Multicast/Broadcast Traffic: %5
Security Logging:
Log Dropped Packets: %6
Log Successful Connections: %7This event generates every time Windows Firewall service starts.
This event shows Windows Firewall settings that were in effect when the Windows Firewall service started.
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"MPSSVC Rule-Level Policy Change"
LEFT/RIGHT arrow keys for navigation
Back to List