Security Compliance
Tune out Windows Filtering Platform on SEM and on a Windows agent
This article describes how to tune out Windows Filtering Platform (WFP) on SEM and on a Windows agent. WFP is a new application in Windows 7 and Windows 8 and Server 2008/2012 that logs firewall and IPsec related events to the System Security Log. These alerts represent accepted background alerts on SEM and consume additional resources on SEM while it processes these events. They are not necessary in an optimized SEM deployment.
First published date
Last published date
Overview
Please note, on environment:
- WFP does not exist if SEM agent is 6.2.0 or newer.
- Windows 7, 8, 8.1, 10
- Windows Server 2008, 2008-R2, 2012, 2012-R2, 2016
Product section
Resolution
Modify the SEM Alert Distribution Policy
- Open SEM Console and log into your SEM Manager from the Manage > Appliances view.
- Next to your SEM Manager, click the gear icon, and then select Policy.
This is the Event Distribution Policy.
- Locate the alerts you want to disable by either browsing the Alert Taxonomy or using the search box under Refine Results.
You can locate all the alerts listed below by typing Windows Security in the search box.
- Select or clear the check boxes in Console, Database, Warehouse or Rules, as appropriate.
- Clear the Console check box to prevent your SEM Manager from showing the alerts in your SEM Console.
- Clear the Database check box to prevent your SEM Manager from storing the alerts in your SEM database.
- Clear the Warehouse check box to prevent your SEM Manager from sending the alerts to an independent database warehouse.
- Clear the Rules check box to prevent your SEM Manager from processing the alerts against your SEM rules.
- Select any check box to enable processing of the alerts for any of the four levels listed above.
- If you want to save your changes and keep working, click Apply, or click OK if you want to save your changes and exit the Alerts Distribution Policy window.
Table of Alerts with Security Auditing Provider SIDs
The Provider SID value in the following alerts match the format, Windows Security, Auditing Event ID, where Event ID is one of the Windows Event ID listed below.
| Alert Name | Windows Event ID |
| TCPTrafficAudit | 5152, 5154, 5156, 5157, 5158, 5159 |
| IPTrafficAudit | 5152, 5154, 5156, 5157, 5158, 5159 |
| UDPTrafficAudit | 5152, 5154, 5156, 5157, 5158, 5159 |
| ICMPTrafficAudit | 5152, 5156, 5157, 5158, 5159 |
| RoutingTrafficAudit | 5152, 5156 |
| PPTPTrafficAudit | 5152 |
Table of Description by Event ID
| Event ID | Brief Description |
| 5152 | Windows Filtering Platform blocked a packet. |
| 5154 | Windows Filtering Platform permitted an application or service to listen on a port for incoming connections. |
| 5156 | Windows Filtering Platform allowed a connection. |
| 5157 | Windows Filtering Platform blocked a connection. |
| 5158 | Windows Filtering Platform permitted a bind to a local port. |
| 5159 | Windows Filtering Platform blocked a bind to a local port. |
Additional Suggested Settings
Set the following subcategories to No Auditing to tune Windows Advanced Audit Policy logging for LEM implementation:
- Logon/Logoff > Audit IPsec Extended Mode
- Logon/Logoff > Audit IPsec Main Mode
- Logon/Logoff > Audit IPsec Quick Mode
- Object Access > Audit Filtering Platform Connection
- Object Access > Audit Filtering Platform Packet Drop
- Policy Change > Audit Filtering Platform Policy Change
- System > Audit IPsec Driver
Set a WFP subcategory to No Auditing using Group Policies
- Navigate to Control Panel > Administrative Tools, and then open Group Policy Management.
- Open Group Policy Management Editor for the domain policy you want to edit. For example, click Default Domain Policy, and then click Action > Edit.
- Under Computer Configuration, navigate to Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies.
- Click each policy under this node to view and edit its subcategories.
- In the right pane, click the subcategory you want to edit, and then click Action > Properties.
- On the Policy tab, select Configure the following audit events. Do not select Success or Failure.
Note: To edit WFP auditing using local policy instead, open Administrative Tools > Local Security Policy, and expand Advanced Audit Policy Configuration.
Additional Resources
For additional information about Advanced Audit Policy Configuration, see the Microsoft TechNet article, Advanced Security Auditing FAQ (© 2018 Microsoft, available at https://www.microsoft.com/en-us/, obtained on December 17, 2018)
For information about tuning standard Windows audit policies for SEM implementation on a non-WFP computer, see:
- Audit Policy and Best Practices
- Disabling Windows Filtering Platform Alerts Using Alert Distribution Policy.
- SEM Manager crashes after a high number of alerts from Windows 7 or Windows Server 2008
If you are required to log these WFP events, contact SolarWinds support for a connector that reads and forwards the WFP events.
Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment. You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.