Event Id | 4952 |
Source | Microsoft-Windows-Security-Auditing |
Description | A rule has been ignored because its major version number was not recognized by Windows Firewall. %t Profile:%t%1 Ignored Rule: %tID:%t%2 %tName:%t%3 |
Event Information | According to Microsoft : Cause : This event is logged when a rule has been ignored because its major version number was not recognized by Windows Firewall. Resolution : If user receive this error, need to review the following actions: 1.If user is supporting multiple versions of Windows and want to deploy only one set of rules to all of them, then create the rule set on a computer running the oldest version of Windows that you support. Later versions of Windows usually support settings introduced in earlier versions. You must still test the policies for compatibility with all versions of Windows to which you want to deploy them, because sometimes an older setting is no longer implemented in newer versions of Windows. 2.If the range of Windows versions that you need to support do not have a common firewall rules engine version number that they can all process, then you need to deploy a set of rules separately to each group. For example, if one set of computers is running a version of Windows that supports only v2.0 firewall rules, and another set of computers is running a version of Windows that supports only a minimum of version v3.0 firewall rules, then you must create both v2.0 and a v3.0 rule sets, and ensure that each rule set is deployed to only the computers with the appropriate version of Windows. Windows Management Instrumentation (WMI) filters can be used with Group Policy to specify criteria such as operating system version number to which the Group Policy object is to apply. |
Reference Links | Event ID 4951 from source Microsoft-Windows-Security-Auditing |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.