Firewall settings in NIS

Sorry all, I know my questions get scattered but this is an important issue to me. Since I will be moving to NIS 201 (possible 2011 but the question is valid regardless of which one I choose), I have questions about firewall setting

 

1. Once the new NIS is installed, do I have to give "permission" for things that do automatic checks for updates such as microsoft updates? Like mine is set to check daily. So the first time it trys to check, will I have to give to ok for it to procede?

 

2. Once i set a specific firewall rule ( such as blocking a port), will I have to reset that again after a product version build updates?

Example(versions made up), I have NIS 2010 17.1.1  I set firewall to block incoming to port 3389.

 Then new version build  of NIS 2010 17.2.0 gets insatlled. Do I have to then recreate that specific firewall rule? Or will it "transfer" over to the new version? Do newer builds often/always create a new firewall?