1. CPU: Intel Core2 Duo E6850
2. OS: Windows Vista Ultimate (6.0.6000) (x64)
4. Symptoms: GUI is not working properly and firewall events are not logged if you are using the computer remotely (RDP) or if you are not logged on at all.
Scenario 1: Log on to your computer and use it for a while. “View firewall events” and confirm that events are logged as usual. Connect to your computer from another machine using Remote Desktop. Your session on the physical console will be disconnected and you are now connected remotely. Wait for a while and “View firewall events”. No events has been logged since you disconnected from console!
Still connected remotely, start a new application that requests network access. Usually a balloon dialog will ask you to allow or block the application, but while connected remotely these balloon dialogs do not show up and network access will be blocked for the application.
Scenario 2: Reboot the computer. Wait a few minutes before you log on. Click “View firewall events”. No events has been logged since you rebooted, even though there have been several intrusion attempts. While you are logged on events are logged as usual.
Conclusion: Firewall events are not logged and balloon dialogs do not show if you are not logged on to the physical console.
6. CFP Settings: Firewall: Custom Policy Mode, Defense+: Disabled