Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Invoke-IcingaCheckFirewall reports NotConfigured on Windows Server 2025 with GPO-managed firewall

Abierto Apto para principiantes
#480 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
2/5
Tiempo estimado
1-3 horas
Aptitud para principiantes
76/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Tranquilo
Stack tecnológico
powershell

Línea de trabajo

Comienza con Invoke-IcingaCheckFirewall e inspecciona la llamada a Get-NetFirewallProfile mostrada en el issue. Compara el almacén de directivas predeterminado con ActiveStore en un sistema Windows Server 2025 administrado mediante GPO. Se considera completado cuando el check evalúa el estado efectivo del perfil y devuelve OK cuando Domain, Private y Public están habilitados.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Describe the bug

Invoke-IcingaCheckFirewall reports a critical state on Windows Server 2025 when the Windows Firewall is managed by Group Policy.

The check reports all firewall profiles as NotConfigured, although the effective firewall state is enabled for Domain, Private and Public profiles.

The issue appears to be related to the plugin using Get-NetFirewallProfile without specifying -PolicyStore ActiveStore.

On the affected system, the default policy store returns NotConfigured, while the effective active policy store returns True.

To Reproduce

  1. Install Icinga for Windows on a Windows Server 2025 system with Windows Firewall managed through Group Policy.

  2. Verify the default firewall profile state:

Get-NetFirewallProfile | Select-Object Name, Enabled

Output:

Name    Enabled
----    -------
Domain  NotConfigured
Private NotConfigured
Public  NotConfigured
  1. Verify the effective firewall profile state using the Active Policy Store:
Get-NetFirewallProfile -PolicyStore ActiveStore | Select-Object Name, Enabled

Output:

Name    Enabled
----    -------
Domain     True
Private    True
Public     True
  1. Verify the effective firewall state using netsh:
netsh advfirewall show allprofiles

Relevant output:

Domain Profile Settings:
State                                 ON

Private Profile Settings:
State                                 ON

Public Profile Settings:
State                                 ON
  1. Run the Icinga for Windows firewall check:
Import-Module icinga-powershell-framework
Import-Module icinga-powershell-plugins

Invoke-IcingaCheckFirewall `
    -FirewallProfile Domain,Private,Public `
    -Enabled `
    -Verbosity 3

Output:

[CRITICAL] Firewall profiles [CRITICAL] Firewall Profile Domain, Firewall Profile Private, Firewall Profile Public (All must be [OK])
\_ [CRITICAL] Firewall Profile Domain: Value NotConfigured is not matching threshold Enabled
\_ [CRITICAL] Firewall Profile Private: Value NotConfigured is not matching threshold Enabled
\_ [CRITICAL] Firewall Profile Public: Value NotConfigured is not matching threshold Enabled
  1. Inspect the implementation of the check:
(Get-Command Invoke-IcingaCheckFirewall).Definition

Relevant code:

$FirewallData = (Get-NetFirewallProfile -Name $singleprofile -ErrorAction SilentlyContinue);

$FirewallCheck = New-IcingaCheck `
    -Name "Firewall Profile $singleprofile" `
    -Value $FirewallData.Enabled

The check currently reads the default policy store, which returns NotConfigured on Windows Server 2025 systems where Windows Firewall is managed through Group Policy.

The effective firewall state is available through:

Get-NetFirewallProfile -PolicyStore ActiveStore

which correctly returns:

Domain     True
Private    True
Public     True
Possible root cause

Invoke-IcingaCheckFirewall currently uses:

Get-NetFirewallProfile -Name $singleprofile

On Windows Server 2025 with GPO-managed firewall profiles this returns:

NotConfigured

while the effective state is available via:

Get-NetFirewallProfile -PolicyStore ActiveStore

which correctly returns:

True

for all enabled firewall profiles.

Expected behavior

The check should evaluate the effective firewall state.

On systems where the firewall is managed by Group Policy, the effective state can be retrieved with:

Get-NetFirewallProfile -PolicyStore ActiveStore

Expected result:

Domain  Enabled
Private Enabled
Public  Enabled

The check should return OK when the effective firewall state is enabled.

Your Environment

  • Version used (icinga2 --version):
    Icinga Master: r2.16.1-1
    Windows Agent: v2.16.1
    icinga-powershell-framework: 1.14.2
    icinga-powershell-plugins: 1.14.1

  • Operating System and version:
    Icinga Master: Debian 12
    Windows Server 2025 OsBuildNumber: 26100

Lenguaje dominante
PowerShell
Estrellas
55
Forks
31
Merge medio
4 d 5 h
PR fusionados (30 d)
6

Preparar el entorno

Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de Icinga/icinga-powershell-plugins

Todos los issues de Icinga/icinga-powershell-plugins

Issues similares

Más issues de Observability & SRE

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.