Internet Connection Firewall (ICF)/Internet Connection Sharing (ICS)
23 July 2000 by Snakefoot | Comment » | Trackback OffDescription:
Provides network address translation (NAT), addressing and name resolution services for all computers on your home network, so they can access the Internet through the shared network- or dial-up- connection.This service is mainly intended for home networks, and it includes its own DNS- and DHCP-Server, and makes use of the NAT module. If on a corporate network with own DNS-, DHCP-, RASS-Server, then ICS might conflict with these. One should instead use Routing And Remote Access or ISA-Server for providing access to the Internet.
Note with Windows XP this service has been extended with a software firewall that can block incoming traffic. The firewall is activated by default when running WinXP Service Pack 2, and will provide enough protection for most users, but if also wanting full control of outgoing traffic, then a 3rd party firewall is required.
Note with Windows Vista the firewall has been moved into a seperate service, which is restricted from creating and accepting network connections. This improves security as it doesn't require network connections like ICS do, for it to function properly.
Related Setting up Internet Connection Sharing
Related Setting up WinXP Internet Connection Firewall (ICF)
Related How to repair the Windows Firewall service if it will not start
More Info MS KB Q234815
More Info MS KB Q250603
More Info MS KB Q310563
More Info MS KB Q317530
More Info MS KB Q827328
Recommended State:
- Disabled, if not sharing your internet connection AND not using the builtin firewall.
- Automatic, if using the builtin firewall or connection sharing.
Default State:
- Win2k: Manual.
- WinXP: Automatic.
- Win2k3: Disabled.
- Vista: Disabled.
Process Name:
- svchost.exe -k netsvcs (SharedAccess)
Supports:
- None
Depends:
- Base Filtering Engine (Vista+)
- Remote Access Connection Manager
- Application Layer Gateway (WinXP/Win2k3 only)
- Network Connections (WinXP+)
- Network Location Awareness (WinXP/Win2k3 only)
- Remote Access Auto Connection Manager (Win2k3 only)
- Universal Plug and Play Device Host (WinXP only - unofficially)
- SSDP Discovery (WinXP only - unofficially)
- Windows Management Instrumentation (Vista+)
Tags:
Category:
Updated: 23 September 2007