Windows Defender Firewall with Advanced Security: Scoped Inbound Rules
Windows Defender Firewall with Advanced Security (WFAS) manages Windows Defender Firewall rules through the wf.msc Microsoft Management Console snap-in. This walkthrough creates a custom inbound rule for a service listening on TCP port 8443, limited to an approved management subnet and the Domain profile.
Replace the port, executable path, and subnet with the values approved for your service. On domain-managed systems, create or edit the rule in the controlling Group Policy Object (GPO); a local rule can be overridden by policy. The MMC requires administrator rights to change local firewall policy.
Step 1: Open WFAS and Review the Inbound Rules
Launch the Firewall MMC Snap-in
ConsoleOpen the local Windows Firewall with Advanced Security console, then select Inbound Rules. Review the existing rules for the application or port before adding another one. On a domain device, check whether the console is connected to Local Computer or editing a GPO.
Win + Rwf.mscβ― View Expected Console Output
Console tree:Windows Defender Firewall with Advanced Security Inbound Rules Outbound Rules Connection Security Rules Monitoring
Figure 1: Windows Defender Firewall with Advanced Security (wf.msc) showing the active Inbound Rules table, profiles, and the Actions pane.
Step 2: Start a Custom Inbound Rule
Choose Custom to Expose the Full Wizard
Rule TypeWith Inbound Rules selected, choose Action β New Rule. On the Rule Type page, choose Custom. The Port option is shorter, but Custom exposes the Program and Scope pages so the rule can be limited to the service executable and approved sources.
Inbound Rules β Action β New Rule β Custom β Nextβ― View Expected Console Output
Program page: This program path: <full path to the service executable>
Select Next. Use the specific executable when the service has a dedicated program.Step 3: Set the Protocol and Local Port
Allow TCP 8443 for the Service
Protocol and PortsOn Protocol and Ports, choose TCP and Specific local ports, then enter 8443. For inbound TCP/UDP rules, this page configures the local listening port. The remote client source port is not configured here and is normally dynamic.
Protocol type: TCPLocal port: Specific local ports β 8443β― View Expected Console Output
The rule matches TCP connections addressed to local port 8443.
Figure 2: New Inbound Rule Wizard on the Protocol and Ports page selecting TCP protocol and specifying local destination port 8443.
Step 4: Restrict the Scope to the Management Subnet
Limit Remote Addresses to Approved Clients
ScopeOn Scope, leave local addresses as Any IP address unless this server listens on multiple networks and the service should be reachable only on a specific interface address. Under remote addresses, choose These IP addresses and add the approved management subnet. For this walkthrough, enter 10.20.30.0/24; replace it with the source subnet from your network plan.
Which local IP addresses does this rule apply to? Any IP address
Which remote IP addresses does this rule apply to? These IP addresses: 10.20.30.0/24β― View Expected Console Output
Only clients whose source address is in 10.20.30.0/24 match this rule.
Figure 3: New Inbound Rule Wizard on the Scope page with the modal dialog adding remote management subnet 10.20.30.0/24.
Step 5: Choose the Action and Network Profile
Allow Only the Intended Service Traffic
PolicySelect Allow the connection only if this traffic is required and the service is protected by its own authentication and authorization controls. Apply the rule to Domain only when the host is domain joined and the service should accept traffic only on that network profile. Finish with a unique name and description so another administrator can identify its purpose and owner.
Action: Allow the connectionProfile: DomainName: Admin Portal - TCP 8443 - Management SubnetDescription: Inbound access to the admin portal from 10.20.30.0/24.β― View Expected Console Output
Rule created with a narrow program, port, source subnet, and profile scope.Step 6: Verify the Rule and Test from an Approved Client
Inspect the Effective Rule and Test Reachability
VerificationConfirm the rule is enabled with the intended direction, action, profile, local port, and remote address. Test from a client inside the approved subnet, then verify a client outside that scope is not granted access by this rule. Other broader allow rules can independently permit traffic, so evaluate the complete effective policy when validating the negative test.
$Rule = Get-NetFirewallRule -DisplayName 'Admin Portal - TCP 8443 - Management Subnet'$Rule | Select-Object DisplayName, Enabled, Profile, Direction, Action$Rule | Get-NetFirewallPortFilter | Select-Object Protocol, LocalPort$Rule | Get-NetFirewallAddressFilter | Select-Object LocalAddress, RemoteAddress
# Run from an approved management client:Test-NetConnection admin-portal.contoso.com -Port 8443β― View Expected Console Output
Enabled : TrueProfile : DomainDirection : InboundAction : AllowProtocol : TCPLocalPort : 8443RemoteAddress : 10.20.30.0/24TcpTestSucceeded : TrueFor the supported wizard workflow, see Microsoftβs Configure firewall rules with Group Policy. For rule details and scoping guidance, see Windows Firewall rule authoring.