<div class="content"><p>The QueryFirewallConfiguration method determines whether the
<a href="4e68c532-eb40-46bd-84c3-3089de921255" data-linktype="relative-path">firewall state</a> of the
server is compatible with use in a <a href="b30bcd1c-8ff6-46d2-a27e-61bd85ace9f4#gt_acd8b49c-8762-48fd-9272-26a03643322b" data-linktype="relative-path">failover cluster</a>. The
firewall settings that constitute failover cluster compatibility are
implementation-specific. When the server firewall enforces policies specified
in <a href="../ms-fasp/55e50895-2e1f-4479-b130-122f9dc0265f" data-linktype="relative-path">[MS-FASP]</a>,
the server SHOULD determine the firewall state according to how the group of
rules is enabled, as specified later in this section.</p><p>The server SHOULD support this method even if the server <b>Initialization
State</b> is FALSE.</p><dl>
<dd>
<div><pre> HRESULT QueryFirewallConfiguration(
   [out] BOOLEAN* serverRulesEnabled,
   [out] BOOLEAN* mgmtRulesEnabled
 );
</pre></div>
</dd></dl><p><b>serverRulesEnabled: </b>An output parameter that
MUST be set on a successful return. The value MUST be TRUE if firewall settings
are compatible with server-to-server communication in a failover cluster. When
the server firewall enforces policies specified in [MS-FASP], the server SHOULD
set this value to TRUE if the group of rules with the localized name
&#34;Failover Clusters&#34; is enabled.</p><dl>
<dd>
<table><thead>
  <tr>
   <th>
   <p>Value</p>
   </th>
   <th>
   <p>Meaning</p>
   </th>
  </tr>
 </thead><tbody><tr>
  <td>
  <p>TRUE</p>
  <p>-128 — -1</p>
  </td>
  <td>
  <p>Firewall settings allow the traffic specified
  previously.</p>
  </td>
 </tr><tr>
  <td>
  <p>FALSE</p>
  <p>0</p>
  </td>
  <td>
  <p>Firewall settings do not allow the traffic specified
  previously.</p>
  </td>
 </tr><tr>
  <td>
  <p>TRUE</p>
  <p>1 — 128</p>
  </td>
  <td>
  <p>Firewall settings allow the traffic specified
  previously.</p>
  </td>
 </tr></tbody></table>
</dd></dl><p><b>mgmtRulesEnabled: </b>An output parameter that
MUST be set on a successful return. The value MUST be TRUE if firewall settings
are compatible with failover cluster management components. When the server
firewall enforces policies specified in [MS-FASP], the server SHOULD set this
value to TRUE if the group of rules with the localized name &#34;Failover
Cluster Manager&#34;<a id="Appendix_A_Target_29"></a><a aria-label="Product behavior note 29" href="6ea29e14-9c33-4927-90a8-258fd1d6d042#Appendix_A_29" data-linktype="relative-path">&lt;29&gt;</a> is enabled.</p><dl>
<dd>
<table><thead>
  <tr>
   <th>
   <p>Value</p>
   </th>
   <th>
   <p>Meaning</p>
   </th>
  </tr>
 </thead><tbody><tr>
  <td>
  <p>TRUE</p>
  <p>-128 — -1</p>
  </td>
  <td>
  <p>Firewall settings allow the traffic specified
  previously.</p>
  </td>
 </tr><tr>
  <td>
  <p>FALSE</p>
  <p>0</p>
  </td>
  <td>
  <p>Firewall settings do not allow the traffic specified previously.</p>
  </td>
 </tr><tr>
  <td>
  <p>TRUE</p>
  <p>1 — 128</p>
  </td>
  <td>
  <p>Firewall settings allow the traffic specified
  previously.</p>
  </td>
 </tr></tbody></table>
</dd></dl><p><b>Return Values: </b>A signed 32-bit value that
indicates return status. If the method returns a negative value, it has failed.
Zero or positive values indicate success, with the lower 16 bits in positive
nonzero values containing warnings or flags defined in the method
implementation. For more information about Win32 error codes and <a href="../ms-dtyp/a9046ed2-bfb2-4d56-a719-2824afce59ac" data-linktype="relative-path">HRESULT</a>
values, see <a href="../ms-erref/1bc92ddf-b79e-413c-bbaa-99a5281a6c90" data-linktype="relative-path">[MS-ERREF]</a>
sections <a href="../ms-erref/18d8fbe8-a967-4f1c-ae50-99ca8e491d2d" data-linktype="relative-path">2.2</a>
and <a href="../ms-erref/0642cb2f-2075-4469-918c-4441e69c548a" data-linktype="relative-path">2.1</a>.</p><dl>
<dd>
<table><thead>
  <tr>
   <th>
   <p>Return value/code</p>
   </th>
   <th>
   <p>Description</p>
   </th>
  </tr>
 </thead><tbody><tr>
  <td>
  <p>0x00000000</p>
  <p>S_OK</p>
  </td>
  <td>
  <p>The call was successful.</p>
  </td>
 </tr></tbody></table>
</dd>
<dd>
<p>For any other condition, this method MUST return a
value that is not one of the values listed in the preceding table. The client
MUST behave in one consistent, identical manner for all values that are not
listed in the preceding table.</p>
</dd></dl><p>Exceptions Thrown: No exceptions are thrown beyond those
thrown by the underlying <a href="b30bcd1c-8ff6-46d2-a27e-61bd85ace9f4#gt_8a7f6700-8311-45bc-af10-82e10accd331" data-linktype="relative-path">RPC</a>
protocol <a href="../ms-rpce/290c38b1-92fe-4229-91e6-4fc376610c15" data-linktype="relative-path">[MS-RPCE]</a>.</p><p>The <a href="b30bcd1c-8ff6-46d2-a27e-61bd85ace9f4#gt_e127848e-c66d-427d-b3aa-9f904fa4ada7" data-linktype="relative-path">opnum</a>
field value for this method is 7.</p><p>When processing this call the server MUST do the following:</p><ul><li><p><span><span> 
</span></span>Query the firewall state for the server to determine whether the <a href="b30bcd1c-8ff6-46d2-a27e-61bd85ace9f4#gt_77375add-f998-4153-843d-e3cfafc996cc" data-linktype="relative-path">Firewall Rules</a> that meet
the <i>serverRulesEnabled</i> category are present and enabled.</p>
</li><li><p><span><span> 
</span></span>Query the firewall state for the server to determine whether the
Firewall Rules that meet the <i>mgmtRulesEnabled</i> category are present and
enabled.</p>
</li></ul><p>Return the following information to the client:</p><ul><li><p><span><span> 
</span></span><i>serverRulesEnabled</i> and <i>mgmtRulesEnabled</i> set as
described previously.</p>
</li></ul></div>