Forum Discussion

Bass_67's avatar
Bass_67
Brass Contributor
Sep 01, 2023
Solved

KB5029263 broke windows firewall on Windows 11

Hello,

 

I'm experiencing the following issue with the latest Windows 11 security update (KB5029263)

 

When I arrive at the office, I connect via an RJ45 cable and an ethernet card.
The ethernet card tells me that I am in the domain, and the Windows firewall tells me that I have a network connection to the domain.

 

When I connect to a WIFI terminal in the domain, the WIFI card tells me that I am in the domain, and the Windows firewall tells me that I have a network connection with the domain.

 

If I reconnect to the local network via the ethernet card, I have a problem:
The ethernet card tells me that I am in the domain, and the Windows firewall tells me that I have a public network connection.

 

I tested with a PC running Windows 10, this problem does not occur.

If I uninstall KB5029263, the problem disappears.

 

Is Microsoft aware of this bug?

  • Eslam_Essam's avatar
    Eslam_Essam
    Oct 13, 2023

    RiverWalker78 hi, the public fix will be in October (last week) for Win11 22H2 and November (2nd week ) for Win11 21H2 

27 Replies

  • MrcsJvnn's avatar
    MrcsJvnn
    Copper Contributor
    Can confirm, the issue still exists with Windows 11 22H2 with October updates.
    • Bass_67's avatar
      Bass_67
      Brass Contributor

      MrcsJvnnyes i always have the problem

      Eslam_Essamsays the public fix will be in October (last week) for Win11 22H2 and November (2nd week ) for Win11 21H2

       

      we need to wait 2-3 week to see if Microsoft solve the problem

      • mcotton705's avatar
        mcotton705
        Copper Contributor

        Bass_67 

         

        I can confirm that Windows 11 22H2 with October updates still has the issue. There is a registry tweak someone further up in the comments suggested that got me working again. 

         

        Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters\Internet\
        
         
        
        Change EnableActiveProbing = 1 to EnableActiveProbing = 0
  • Chet2142's avatar
    Chet2142
    Copper Contributor
    We had the same issues since that update installed in our environment as well. You can be on either ethernet or wifi but the process of switching between the two would cause the profile to switch from domain to public. We found the only way to switch between them was to deactivate the wifi prior to switching to wired connection. Transitioning from wired to wireless was not an issue for us.
    • Bass_67's avatar
      Bass_67
      Brass Contributor
      This is exactly the case I encounter.
  • cc-viserion's avatar
    cc-viserion
    Copper Contributor

    Bass_67 

     

    The team here has been dealing with this for several weeks now. I've actually seen it happen without being connected to both wifi and ethernet. We are on day 3 of adjusting this reg key and so far, we haven't seen the issue come back.

     

    Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters\Internet\
    
     
    
    Change EnableActiveProbing = 1 to EnableActiveProbing = 0

     

    This stopped the constant probing that seemed to be happening for no reason within the NetworkProfile Event Viewer log. Prior to changing this reg key it would check several times per hour and eventually it would switch from a domain firewall profile to a guest firewall profile.

     

    • Bass_67's avatar
      Bass_67
      Brass Contributor
      Thank you for this tip, but this does not solve the problem of the wrong type of firewall connection
  • Lukas's avatar
    Lukas
    Copper Contributor
    We just received an information from Microsoft: This is a known issue and the update Team is working on a fix. Until the release of the fix, the workaround is to use only one network connection at a time:
    wether just cable and disable WIFI, or just WIFI and unplug cable
    • MindsUser's avatar
      MindsUser
      Copper Contributor

      Lukason an official page https://support.microsoft.com/en-us/topic/august-8-2023-kb5029263-os-build-22621-2134-f8d4d3de-47c1-40e1-a2e6-97c2770ee2e8 under "Known issues in this update" section you can read "Microsoft is not currently aware of any issues with this update."

      • Lukas's avatar
        Lukas
        Copper Contributor
        this is kind of interessting, as they clearly told us, that "this is a known issue registered by Microsoft".
        I guess it'll take some time until it is officially recognized und published as a bug.
    • Bass_67's avatar
      Bass_67
      Brass Contributor
      Bad news.
      The September 2023 update does not fix the issue.
  • Bass_67's avatar
    Bass_67
    Brass Contributor
    maybe people don't realize the problem, because they don't have authentication restrictions on their pro connection

    but the problem is real
  • infobri's avatar
    infobri
    Copper Contributor
    Hello, we also encounter this problem and we made the same conclusion as you, the problem comes from the KB5029263 update.
    I reported this issue to Microsoft via Feedback Hub, but there doesn't seem to be many people talking about it, we'll see when it's fixed....
    Note that KB5029351 (preview update released on 08/22) does not correct the problem.
  • Lukas's avatar
    Lukas
    Copper Contributor

    Bass_67 We encounter the same problem. We did open a ticket regarding this, but no answer so far

Resources