<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cupfighter.net &#187; Event ID 5156</title>
	<atom:link href="http://www.cupfighter.net/index.php/tag/event-id-5156/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cupfighter.net</link>
	<description>A blog by Schuberg Philis colleagues</description>
	<lastBuildDate>Thu, 09 Feb 2012 14:27:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Get rid of Event ID 5156: The Windows Filtering Platform has allowed a connection</title>
		<link>http://www.cupfighter.net/index.php/2009/10/get-rid-of-event-id-5156-the-windows-filtering-platform-has-allowed-a-connection/</link>
		<comments>http://www.cupfighter.net/index.php/2009/10/get-rid-of-event-id-5156-the-windows-filtering-platform-has-allowed-a-connection/#comments</comments>
		<pubDate>Mon, 05 Oct 2009 12:47:49 +0000</pubDate>
		<dc:creator>Cupfighter</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Windows 2008]]></category>
		<category><![CDATA[Event ID 5156]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[windows vista]]></category>

		<guid isPermaLink="false">http://www.cupfighter.net/?p=568</guid>
		<description><![CDATA[When you install McAfee on Windows Server 2008, and probably Windows Vista also, you can get a lot of messages in your security log. Like this one: Event ID 5156 means that WFP has allowed a connection. When most connections are allowed your security log will fill up very fast. You can disable Object Access [...]]]></description>
			<content:encoded><![CDATA[<p>When you install McAfee on Windows Server 2008, and probably Windows Vista also, you can get a lot of messages in your security log. Like this one:</p>
<p><img class="alignnone size-full wp-image-569" src="http://www.cupfighter.net/wp-content/uploads/2009/10/ID-5156.jpg" alt="ID 5156" width="455" height="317" /></p>
<p>Event ID 5156 means that WFP has allowed a connection. When most connections are allowed your security log will fill up very fast.</p>
<p>You can disable Object Access auditing but then you&#8217;ll miss other events which might be of interest. So, instead, let&#8217;s just disable Success Auditing for Filtering Platform Connections. It&#8217;s not possible to disable auditing subcategories with a policy or other GUI tool, but I found out that you can enable and disable specific subcategories with a special command-line tool: Auditpol.exe, which is included with Windows Vista and Windows Server 2008. I used the following command:</p>
<p>auditpol /set /subcategory:&#8221;Filtering Platform Connection&#8221; /success:disable /failure:enable</p>
<p>As you can see this disables Success auditing for the Filtering Platform Connection subcategory.</p>
<p>For more info check out this article:</p>
<p><a href="http://msdn.microsoft.com/en-us/library/bb309058(VS.85).aspx">http://msdn.microsoft.com/en-us/library/bb309058(VS.85).aspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.cupfighter.net/index.php/2009/10/get-rid-of-event-id-5156-the-windows-filtering-platform-has-allowed-a-connection/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

