<div class="content" name="QueryFirewallConfiguration" uuid="e5185ec2-df7c-495f-8820-ad5e2634271a"><p>The QueryFirewallConfiguration method determines whether the
<span><a href="4e68c532-eb40-46bd-84c3-3089de921255" data-linktype="relative-path">firewall
state</a></span> of the server is compatible with use in a <span><a href="b30bcd1c-8ff6-46d2-a27e-61bd85ace9f4#gt_acd8b49c-8762-48fd-9272-26a03643322b" data-linktype="relative-path">failover
cluster</a></span>. The firewall settings that constitute failover cluster
compatibility are implementation-specific. When the server firewall enforces
policies specified in <span><a href="../ms-fasp/55e50895-2e1f-4479-b130-122f9dc0265f" data-linktype="relative-path">[MS-FASP]</a></span>,
the server SHOULD determine the firewall state according to how the group of
rules is enabled, as specified later in this section.</p><p>The server SHOULD support this method even if the server <b>Initialization
State</b> is FALSE.</p><dl>
<dd>
<div><pre> HRESULT QueryFirewallConfiguration(
   [out] BOOLEAN* serverRulesEnabled,
   [out] BOOLEAN* mgmtRulesEnabled
 );
</pre></div>
</dd></dl><p><b>serverRulesEnabled: </b>An output parameter that
MUST be set on a successful return. The value MUST be TRUE if firewall settings
are compatible with server-to-server communication in a failover cluster. When
the server firewall enforces policies specified in [MS-FASP], the server SHOULD
set this value to TRUE if the group of rules with the localized name
&#34;Failover Clusters&#34; is enabled.</p><dl>
<dd>
<table><thead>
  <tr>
   <th>
   <p>Value</p>
   </th>
   <th>
   <p>Meaning</p>
   </th>
  </tr>
 </thead><tbody><tr>
  <td>TRUE -128 — -1</td>
  <td>Firewall settings allow the traffic specified previously.</td>
 </tr><tr>
  <td>FALSE 0</td>
  <td>Firewall settings do not allow the traffic specified previously.</td>
 </tr><tr>
  <td>TRUE 1 — 128</td>
  <td>Firewall settings allow the traffic specified previously.</td>
 </tr></tbody></table>
</dd></dl><p><b>mgmtRulesEnabled: </b>An output parameter that
MUST be set on a successful return. The value MUST be TRUE if firewall settings
are compatible with failover cluster management components. When the server
firewall enforces policies specified in [MS-FASP], the server SHOULD set this
value to TRUE if the group of rules with the localized name &#34;Failover
Cluster Manager&#34;<a id="Appendix_A_Target_27"></a><a aria-label="Product behavior note 27" href="6ea29e14-9c33-4927-90a8-258fd1d6d042#Appendix_A_27" data-linktype="relative-path">&lt;27&gt;</a> is enabled.</p><dl>
<dd>
<table><thead>
  <tr>
   <th>
   <p>Value</p>
   </th>
   <th>
   <p>Meaning</p>
   </th>
  </tr>
 </thead><tbody><tr>
  <td>TRUE -128 — -1</td>
  <td>Firewall settings allow the traffic specified previously.</td>
 </tr><tr>
  <td>FALSE 0</td>
  <td>Firewall settings do not allow the traffic specified previously.</td>
 </tr><tr>
  <td>TRUE 1 — 128</td>
  <td>Firewall settings allow the traffic specified previously.</td>
 </tr></tbody></table>
</dd></dl><p><b>Return Values: </b>A signed 32-bit value that
indicates return status. If the method returns a negative value, it has failed.
Zero or positive values indicate success, with the lower 16 bits in positive
nonzero values containing warnings or flags defined in the method
implementation. For more information about Win32 error codes and <span><a href="../ms-dtyp/a9046ed2-bfb2-4d56-a719-2824afce59ac" data-linktype="relative-path">HRESULT</a></span>
values, see <span><a href="../ms-erref/1bc92ddf-b79e-413c-bbaa-99a5281a6c90" data-linktype="relative-path">[MS-ERREF]</a></span>
sections <span><a href="../ms-erref/18d8fbe8-a967-4f1c-ae50-99ca8e491d2d" data-linktype="relative-path">2.2</a></span>
and <span><a href="../ms-erref/0642cb2f-2075-4469-918c-4441e69c548a" data-linktype="relative-path">2.1</a></span>.</p><dl>
<dd>
<table><thead>
  <tr>
   <th>
   <p>Return value/code</p>
   </th>
   <th>
   <p>Description</p>
   </th>
  </tr>
 </thead><tbody><tr>
  <td>0x00000000 S_OK</td>
  <td>The call was successful.</td>
 </tr></tbody></table>
</dd>
<dd>
<p>For any other condition, this method MUST return a
value that is not one of the values listed in the preceding table. The client
MUST behave in one consistent, identical manner for all values that are not
listed in the preceding table.</p>
</dd></dl><p>Exceptions Thrown: No exceptions are thrown beyond those
thrown by the underlying <span><a href="b30bcd1c-8ff6-46d2-a27e-61bd85ace9f4#gt_8a7f6700-8311-45bc-af10-82e10accd331" data-linktype="relative-path">RPC</a></span> protocol <span><a href="../ms-rpce/290c38b1-92fe-4229-91e6-4fc376610c15" data-linktype="relative-path">[MS-RPCE]</a></span>.</p><p>The <span><a href="b30bcd1c-8ff6-46d2-a27e-61bd85ace9f4#gt_e127848e-c66d-427d-b3aa-9f904fa4ada7" data-linktype="relative-path">opnum</a></span> field value
for this method is 7.</p><p>When processing this call the server MUST do the following:</p><ul><li><p><span><span> 
</span></span>Query the firewall state for the server to determine whether the <span><a href="b30bcd1c-8ff6-46d2-a27e-61bd85ace9f4#gt_77375add-f998-4153-843d-e3cfafc996cc" data-linktype="relative-path">Firewall
Rules</a></span> that meet the <i>serverRulesEnabled</i> category are present
and enabled.</p>
</li><li><p><span><span> 
</span></span>Query the firewall state for the server to determine whether the
Firewall Rules that meet the <i>mgmtRulesEnabled</i> category are present and
enabled.</p>
</li></ul><p>Return the following information to the client:</p><ul><li><p><span><span> 
</span></span><i>serverRulesEnabled</i> and <i>mgmtRulesEnabled</i> set as
described previously.</p>
</li></ul></div>