Skip to content

Create a Scoped Inbound Windows Firewall Rule

Windows Defender Firewall rules should match the service, protocol, port, network profile, and source addresses that actually need access. This tutorial adds a narrowly scoped TCP rule with PowerShell, verifies the active rule, and shows how to remove it during rollback.

Use an elevated PowerShell session and replace the example port and management subnet with values approved for your environment. Confirm you have console or out-of-band access before changing firewall policy on a remote server.


Step 1: Inspect the Firewall Profiles and Existing Rules

01

Check the Active Profiles and Port Rules

Baseline

Confirm which profiles are enabled and check for an existing rule covering the application port. Avoid creating a duplicate rule whose broader scope would override your intended access design.

Terminal window
Get-NetFirewallProfile | Select-Object Name, Enabled, DefaultInboundAction
# Keep each matching port filter associated with its firewall rule name.
$ActiveRules = Get-NetFirewallRule -PolicyStore ActiveStore |
Where-Object { $_.Enabled -eq $true }
foreach ($Rule in $ActiveRules) {
$PortFilter = $Rule | Get-NetFirewallPortFilter
if ($PortFilter.LocalPort -contains '8443' -or $PortFilter.LocalPort -contains 'Any') {
[pscustomobject]@{
DisplayName = $Rule.DisplayName
Direction = $Rule.Direction
Action = $Rule.Action
Profile = $Rule.Profile
Protocol = $PortFilter.Protocol
LocalPort = $PortFilter.LocalPort -join ','
}
}
}
❯ View Expected Console Output
Name Enabled DefaultInboundAction
---- ------- --------------------
Domain True Block
Private True Block
Public True Block

Step 2: Add an Inbound Rule for the Management Subnet

02

Limit the Rule to a Known Source Range

Rule Definition

Add an allow rule for the example service on TCP port 8443, only on the Domain profile and only from the approved management subnet. Replace 10.20.30.0/24 with the actual IPv4 or IPv6 range. If your service uses a different profile or port, scope the rule accordingly.

Terminal window
$Rule = @{
DisplayName = 'Admin Portal - Management Subnet Only'
Direction = 'Inbound'
Action = 'Allow'
Protocol = 'TCP'
LocalPort = 8443
RemoteAddress = '10.20.30.0/24'
Profile = 'Domain'
}
New-NetFirewallRule @Rule
❯ View Expected Console Output
DisplayName : Admin Portal - Management Subnet Only
Enabled : True
Direction : Inbound
Action : Allow

Step 3: Verify the Effective Rule and Test from Both Sides

03

Confirm the Port and Remote Address Scope

Verification

Inspect the rule and its address and port filters in the active policy store. From an approved management host, test the service port. Also test from a host outside the permitted range and confirm it cannot connect. An allow rule alone does not prove that the application is listening or that upstream network controls permit traffic.

Terminal window
$FirewallRule = Get-NetFirewallRule -DisplayName 'Admin Portal - Management Subnet Only'
$FirewallRule | Get-NetFirewallAddressFilter
$FirewallRule | Get-NetFirewallPortFilter
# Run on an authorized remote client:
Test-NetConnection server.contoso.com -Port 8443
❯ View Expected Console Output
RemoteAddress : 10.20.30.0/24
Protocol : TCP
LocalPort : 8443
TcpTestSucceeded : True

Step 4: Roll Back the Change if Needed

04

Remove Only the Rule You Added

Rollback

If the rule causes an issue or is no longer needed, remove it by its unique display name and verify it is gone. Do not disable the firewall profile to troubleshoot one service.

Terminal window
Remove-NetFirewallRule -DisplayName 'Admin Portal - Management Subnet Only'
Get-NetFirewallRule -DisplayName 'Admin Portal - Management Subnet Only' -ErrorAction SilentlyContinue
❯ View Expected Console Output
No matching rule is returned after removal.

See Microsoft’s New-NetFirewallRule reference for supported address, port, profile, and policy-store parameters.

Comments