Windows Defender Firewall rules with PowerShell
Manage Windows Defender Firewall on Windows Server 2022 and 2025: check profiles, open ports, restrict Remote Desktop to your IP, block addresses and log drops.
- Intermediate
- 15 min read
- Updated
Tested on: Windows Server 2022, Windows Server 2025
This guide is not available in your language yet, so it is shown in English.
On this page
Windows Defender Firewall is built into Windows Server and enabled by default. This guide manages it with PowerShell, which is quicker to repeat and document than clicking through the console. Run the commands in PowerShell opened with Run as administrator. Replace 198.51.100.7 with your own IP address.
Before you start
- Sign in with Remote Desktop and keep the session open while you change rules.
- Keep the web console ready if your service page shows one.
- Know your own public IP address(es).
Step 1: Check the profiles
Get-NetFirewallProfile | Select-Object Name, Enabled, DefaultInboundAction, DefaultOutboundActionVerify: all profiles are Enabled : True. The default inbound action blocks traffic that no rule allows. To find which profile your network uses:
Get-NetConnectionProfileStep 2: Open a port
Allow inbound HTTPS for a web server:
New-NetFirewallRule -DisplayName "Allow HTTPS" -Direction Inbound -Protocol TCP -LocalPort 443 -Action AllowMore examples:
New-NetFirewallRule -DisplayName "Allow HTTP" -Direction Inbound -Protocol TCP -LocalPort 80 -Action Allow
New-NetFirewallRule -DisplayName "Game server UDP" -Direction Inbound -Protocol UDP -LocalPort 27015-27030 -Action AllowVerify: from your computer, Test-NetConnection 203.0.113.10 -Port 443 succeeds once a service listens on the port.
Step 3: Restrict Remote Desktop to your addresses
The built-in Remote Desktop rules allow connections from anywhere. Limit them to your addresses:
Set-NetFirewallRule -DisplayGroup "Remote Desktop" -RemoteAddress 198.51.100.7, 203.0.113.0/24Open a second Remote Desktop session to confirm it still works before you close the first. If your address changes often, use a VPN for Remote Desktop instead.
Step 4: Restrict any service to certain addresses
For example, allow SQL Server only from your application server:
New-NetFirewallRule -DisplayName "SQL from app server" -Direction Inbound -Protocol TCP -LocalPort 1433 -RemoteAddress 198.51.100.20 -Action AllowStep 5: Block an address
New-NetFirewallRule -DisplayName "Block 203.0.113.50" -Direction Inbound -RemoteAddress 203.0.113.50 -Action BlockBlock rules take precedence over allow rules.
Review and remove rules
List your own enabled inbound rules with their ports:
Get-NetFirewallRule -Direction Inbound -Enabled True | Where-Object DisplayName -like "Allow*" | Get-NetFirewallPortFilterShow one rule and its address filter, disable or remove it:
Get-NetFirewallRule -DisplayName "Allow HTTPS" | Get-NetFirewallAddressFilter
Disable-NetFirewallRule -DisplayName "Allow HTTPS"
Remove-NetFirewallRule -DisplayName "Allow HTTPS"Log dropped packets
Set-NetFirewallProfile -Profile Domain,Private,Public -LogBlocked True -LogFileName "%SystemRoot%\System32\LogFiles\Firewall\pfirewall.log"Read the log at C:\Windows\System32\LogFiles\Firewall\pfirewall.log to see what was blocked and from where.
Troubleshooting
Remote Desktop stopped working. Your address is not in the rule. From the web console, run Set-NetFirewallRule -DisplayGroup "Remote Desktop" -RemoteAddress Any, then add the right address. See locked out after a firewall change.
A port is allowed but still unreachable. The service is not listening, or listens only on 127.0.0.1. Check with Get-NetTCPConnection -State Listen -LocalPort 443.
Outgoing mail on port 25 fails although the firewall allows it. Outbound port 25 is closed by default on HyperDC VPS. For services bought for a term of 3 months or longer, it is opened on request when you open a support ticket. Until then, send mail through a relay on port 587.
The display group is not found. On servers installed in another language, group names are translated. List them with Get-NetFirewallRule | Select-Object -ExpandProperty DisplayGroup -Unique.
Next steps
- Full baseline: secure a Windows server.
- Remote Desktop errors: Remote Desktop connection problems.
Frequently asked questions
Is the firewall on by default?
Yes. Windows Defender Firewall is enabled on all profiles and blocks unsolicited inbound traffic unless a rule allows it. Installing a role such as IIS usually adds the rules it needs.
Which profile applies to my server?
Usually Public, because the server's network is not a domain or a trusted private network. Rules for All profiles always apply.
Do rules apply to IPv6 as well?
Yes. A rule without address limits applies to IPv4 and IPv6. When you restrict by RemoteAddress, list the IPv6 addresses too if you use them.
Can I use the graphical console instead?
Yes. Run wf.msc to open Windows Defender Firewall with Advanced Security. The PowerShell commands here do the same and are easier to repeat and document.
How do I undo everything?
netsh advfirewall reset restores the default policy and removes your own rules. Run it from the web console if your changes cut your connection.