Create a Scoped Inbound Windows Firewall Rule
Windows Defender Firewall rules should match the service, protocol, port, network profile, and source addresses that actually need access. This tutorial adds a narrowly scoped TCP rule with PowerShell, verifies the active rule, and shows how to remove it during rollback.
Use an elevated PowerShell session and replace the example port and management subnet with values approved for your environment. Confirm you have console or out-of-band access before changing firewall policy on a remote server.
Step 1: Inspect the Firewall Profiles and Existing Rules
Check the Active Profiles and Port Rules
BaselineConfirm which profiles are enabled and check for an existing rule covering the application port. Avoid creating a duplicate rule whose broader scope would override your intended access design.
Get-NetFirewallProfile | Select-Object Name, Enabled, DefaultInboundAction
# Keep each matching port filter associated with its firewall rule name.$ActiveRules = Get-NetFirewallRule -PolicyStore ActiveStore | Where-Object { $_.Enabled -eq $true }foreach ($Rule in $ActiveRules) { $PortFilter = $Rule | Get-NetFirewallPortFilter if ($PortFilter.LocalPort -contains '8443' -or $PortFilter.LocalPort -contains 'Any') { [pscustomobject]@{ DisplayName = $Rule.DisplayName Direction = $Rule.Direction Action = $Rule.Action Profile = $Rule.Profile Protocol = $PortFilter.Protocol LocalPort = $PortFilter.LocalPort -join ',' } }}❯ View Expected Console Output
Name Enabled DefaultInboundAction---- ------- --------------------Domain True BlockPrivate True BlockPublic True BlockStep 2: Add an Inbound Rule for the Management Subnet
Limit the Rule to a Known Source Range
Rule DefinitionAdd an allow rule for the example service on TCP port 8443, only on the Domain profile and only from the approved management subnet. Replace 10.20.30.0/24 with the actual IPv4 or IPv6 range. If your service uses a different profile or port, scope the rule accordingly.
$Rule = @{ DisplayName = 'Admin Portal - Management Subnet Only' Direction = 'Inbound' Action = 'Allow' Protocol = 'TCP' LocalPort = 8443 RemoteAddress = '10.20.30.0/24' Profile = 'Domain'}New-NetFirewallRule @Rule❯ View Expected Console Output
DisplayName : Admin Portal - Management Subnet OnlyEnabled : TrueDirection : InboundAction : AllowStep 3: Verify the Effective Rule and Test from Both Sides
Confirm the Port and Remote Address Scope
VerificationInspect the rule and its address and port filters in the active policy store. From an approved management host, test the service port. Also test from a host outside the permitted range and confirm it cannot connect. An allow rule alone does not prove that the application is listening or that upstream network controls permit traffic.
$FirewallRule = Get-NetFirewallRule -DisplayName 'Admin Portal - Management Subnet Only'$FirewallRule | Get-NetFirewallAddressFilter$FirewallRule | Get-NetFirewallPortFilter
# Run on an authorized remote client:Test-NetConnection server.contoso.com -Port 8443❯ View Expected Console Output
RemoteAddress : 10.20.30.0/24Protocol : TCPLocalPort : 8443TcpTestSucceeded : TrueStep 4: Roll Back the Change if Needed
Remove Only the Rule You Added
RollbackIf the rule causes an issue or is no longer needed, remove it by its unique display name and verify it is gone. Do not disable the firewall profile to troubleshoot one service.
Remove-NetFirewallRule -DisplayName 'Admin Portal - Management Subnet Only'Get-NetFirewallRule -DisplayName 'Admin Portal - Management Subnet Only' -ErrorAction SilentlyContinue❯ View Expected Console Output
No matching rule is returned after removal.See Microsoft’s New-NetFirewallRule reference for supported address, port, profile, and policy-store parameters.