How win7 network discovery function improves computer security

  
 

In some cases (especially if the Windows
7 client coexists with other XP clients), even if network discovery is enabled, it will also occur during network sharing and network access. Some trouble. This is mainly because network discovery also requires some technical support or because of incompatibility between different clients. According to the author's test, after using network discovery, you may encounter the following problems.

One is that if the DNS Clinet function on the client is not enabled, then the network discovery function is activated, and other clients still cannot find this Windows7 clientcomputer
; or this Windows 7 client computer
still can not find its companion in the network neighborhood. This is mainly because network discovery must require the client to start the DNS Clinet function to be effective. If this feature is not enabled, then this configuration will not work. By default, OS
is enabled for this feature. However, for some specific purposes, this DNS Clinet feature will be turned off or temporarily turned off. Such as for security or testing needs and so on. So when network discovery is enabled, system engineers need to first determine if some of the features that the network discovery relies on are enabled. The author also looked up some official information of Microsoft Windows7 and found that if you want to use the network discovery, in addition to enabling the DNS Clinet function, you also need to enable SSDP, UPnP and other services to be able to play the full power of network discovery. Therefore, system administrators need to know the purpose of these services and determine whether they need to be turned on according to actual needs. Note that from a security and performance perspective, the service is not open as much as possible. Instead, follow the minimal principle of opening only the services you need. If you use Windows 7 as a server, you need to pay more attention to this. This can greatly improve its security and operational performance.

The second is to rule out the interference of the firewall. As mentioned above, system engineers can also customize the network discovery policies through firewalls. However, if you are not familiar with the settings of the network firewall, it is very likely that the network discovery will not work properly due to the wrong configuration. If the system administrator unfortunately encounters this situation, what should I do? The author's opinion is to temporarily turn off the firewall and then test whether the network is normal. If everything is normal at this time, it indicates that the fault is caused by the configuration of the firewall. You need to check the configuration of the firewall. If there is still a problem with disabling the firewall, then there is not much relationship with the configuration of the firewall. This is mainly because most network access failures are caused by firewalls. For this reason, I suggest that you should not set a firewall for the client in case of failure to avoid network access. For the server, it is best to set a suitable firewall policy (such as allowing only a specific host to find him on the network, etc.) to ensure its security. Of course this is for enterprise applications. Because enterprises often deploy a separate firewall between the internal network and the external network, such as Cisco's hardware firewall. To do this, deploying a firewall on the client is not necessary. And as a home computer, because there is no independent firewall protection, then configuring the firewall on its computer also has a certain protection.

The third is to choose the right network location. Management measures for network location are provided in Windows 7. By default, it proposes four network locations, namely home network, workgroup, public network and domain. It should be noted here that different network locations correspond to a set of firewall policies. In other words, choose different network locations, which by default correspond to different network configurations and firewall policies. Therefore, when system engineers and network engineers deploy Windows 7 network applications, they also need to pay attention to the differences in firewall policies corresponding to these network locations. This will help them choose the right network location. And sometimes choosing a different location will also affect whether the system enables network discovery. In other words, network location, network discovery and firewall are all integrated. System administrators must truly understand the role of network discovery, so you must understand the links between the three.

Copyright © Windows knowledge All Rights Reserved