Skip to content

NetworkingFirewalls

Windows Defender Firewall rules with PowerShell

Manage Windows Defender Firewall on Windows Server 2022 and 2025: check profiles, open ports, restrict Remote Desktop to your IP, block addresses and log drops.

  • Intermediate
  • 15 min read
  • Updated

Tested on: Windows Server 2022, Windows Server 2025

This guide is not available in your language yet, so it is shown in English.

On this page
  1. Before you start
  2. Step 1: Check the profiles
  3. Step 2: Open a port
  4. Step 3: Restrict Remote Desktop to your addresses
  5. Step 4: Restrict any service to certain addresses
  6. Step 5: Block an address
  7. Review and remove rules
  8. Log dropped packets
  9. Troubleshooting
  10. Next steps

Windows Defender Firewall is built into Windows Server and enabled by default. This guide manages it with PowerShell, which is quicker to repeat and document than clicking through the console. Run the commands in PowerShell opened with Run as administrator. Replace 198.51.100.7 with your own IP address.

Before you start

  • Sign in with Remote Desktop and keep the session open while you change rules.
  • Keep the web console ready if your service page shows one.
  • Know your own public IP address(es).

Step 1: Check the profiles

PowerShell
Get-NetFirewallProfile | Select-Object Name, Enabled, DefaultInboundAction, DefaultOutboundAction

Verify: all profiles are Enabled : True. The default inbound action blocks traffic that no rule allows. To find which profile your network uses:

PowerShell
Get-NetConnectionProfile

Step 2: Open a port

Allow inbound HTTPS for a web server:

PowerShell
New-NetFirewallRule -DisplayName "Allow HTTPS" -Direction Inbound -Protocol TCP -LocalPort 443 -Action Allow

More examples:

PowerShell
New-NetFirewallRule -DisplayName "Allow HTTP" -Direction Inbound -Protocol TCP -LocalPort 80 -Action Allow
New-NetFirewallRule -DisplayName "Game server UDP" -Direction Inbound -Protocol UDP -LocalPort 27015-27030 -Action Allow

Verify: from your computer, Test-NetConnection 203.0.113.10 -Port 443 succeeds once a service listens on the port.

Step 3: Restrict Remote Desktop to your addresses

The built-in Remote Desktop rules allow connections from anywhere. Limit them to your addresses:

PowerShell
Set-NetFirewallRule -DisplayGroup "Remote Desktop" -RemoteAddress 198.51.100.7, 203.0.113.0/24

Open a second Remote Desktop session to confirm it still works before you close the first. If your address changes often, use a VPN for Remote Desktop instead.

Step 4: Restrict any service to certain addresses

For example, allow SQL Server only from your application server:

PowerShell
New-NetFirewallRule -DisplayName "SQL from app server" -Direction Inbound -Protocol TCP -LocalPort 1433 -RemoteAddress 198.51.100.20 -Action Allow

Step 5: Block an address

PowerShell
New-NetFirewallRule -DisplayName "Block 203.0.113.50" -Direction Inbound -RemoteAddress 203.0.113.50 -Action Block

Block rules take precedence over allow rules.

Review and remove rules

List your own enabled inbound rules with their ports:

PowerShell
Get-NetFirewallRule -Direction Inbound -Enabled True | Where-Object DisplayName -like "Allow*" | Get-NetFirewallPortFilter

Show one rule and its address filter, disable or remove it:

PowerShell
Get-NetFirewallRule -DisplayName "Allow HTTPS" | Get-NetFirewallAddressFilter
Disable-NetFirewallRule -DisplayName "Allow HTTPS"
Remove-NetFirewallRule -DisplayName "Allow HTTPS"

Log dropped packets

PowerShell
Set-NetFirewallProfile -Profile Domain,Private,Public -LogBlocked True -LogFileName "%SystemRoot%\System32\LogFiles\Firewall\pfirewall.log"

Read the log at C:\Windows\System32\LogFiles\Firewall\pfirewall.log to see what was blocked and from where.

Troubleshooting

Remote Desktop stopped working. Your address is not in the rule. From the web console, run Set-NetFirewallRule -DisplayGroup "Remote Desktop" -RemoteAddress Any, then add the right address. See locked out after a firewall change.

A port is allowed but still unreachable. The service is not listening, or listens only on 127.0.0.1. Check with Get-NetTCPConnection -State Listen -LocalPort 443.

Outgoing mail on port 25 fails although the firewall allows it. Outbound port 25 is closed by default on HyperDC VPS. For services bought for a term of 3 months or longer, it is opened on request when you open a support ticket. Until then, send mail through a relay on port 587.

The display group is not found. On servers installed in another language, group names are translated. List them with Get-NetFirewallRule | Select-Object -ExpandProperty DisplayGroup -Unique.

Next steps

Frequently asked questions

Is the firewall on by default?

Yes. Windows Defender Firewall is enabled on all profiles and blocks unsolicited inbound traffic unless a rule allows it. Installing a role such as IIS usually adds the rules it needs.

Which profile applies to my server?

Usually Public, because the server's network is not a domain or a trusted private network. Rules for All profiles always apply.

Do rules apply to IPv6 as well?

Yes. A rule without address limits applies to IPv4 and IPv6. When you restrict by RemoteAddress, list the IPv6 addresses too if you use them.

Can I use the graphical console instead?

Yes. Run wf.msc to open Windows Defender Firewall with Advanced Security. The PowerShell commands here do the same and are easier to repeat and document.

How do I undo everything?

netsh advfirewall reset restores the default policy and removes your own rules. Run it from the web console if your changes cut your connection.

Sources

Jelszó létrehozása

Please confirm