Windows Firewall Guide: Configure Inbound and Outbound Rules and Test Them in Real Time

Windows Firewall is a crucial security feature that controls network traffic using Inbound and Outbound rules. This guide covers how to configure firewall rules, block or allow network traffic, and verify whether the rules are working using real-time testing methods such as ping, netstat, and telnet. You'll learn how to: Create Inbound Rules (e.g., block Remote Desktop on Port 3389) Create Outbound Rules (e.g., block internet access on Ports 80 and 443) Verify Firewall Rules using command-line tools Modify or remove rules for troubleshooting By following this step-by-step guide, you can enhance network security and ensure that only authorized traffic flows through your system.

Mar 28, 2025 - 10:33
Updated: 6 days ago
109k
Windows Firewall Guide: Configure Inbound and Outbound Rules and Test Them in Real Time

Quick answer: To create a Windows Firewall rule, open Windows Defender Firewall with Advanced Security (run wf.msc), choose Inbound Rules or Outbound Rules, click New Rule, pick Port, enter the protocol and port, select Allow or Block, choose the profiles, and name it. Test with Test-NetConnection. Block rules override allow rules, so check for conflicts.

Key takeaways

  • Inbound rules control traffic coming to your PC. Outbound rules control traffic leaving it.
  • By default Windows blocks unsolicited inbound traffic and allows outbound. You mostly add allow rules inbound and block rules outbound.
  • If a block rule and an allow rule both match, the block rule wins.
  • Test every rule from another machine, or with Test-NetConnection, so you know it works instead of assuming.
  • Practise on a virtual machine. A wrong outbound block can cut off Windows Update, DNS or your remote session.

What are inbound and outbound firewall rules?

A firewall decides which network traffic may pass, based on rules. Windows Defender Firewall with Advanced Security gives each rule a direction, a protocol, ports, programs and an action.

DirectionControlsTypical use
InboundConnections arriving at this computerAllow a web server on port 443, block Remote Desktop on port 3389
OutboundConnections starting from this computerStop an application from calling out, block a risky port

Each rule also applies to one or more network profiles: Domain, Private and Public. Choose the profiles deliberately. A rule for a coffee-shop Wi-Fi laptop may need to be stricter on Public than at the office on Domain. Microsoft documents the firewall in its Windows Firewall documentation.

How do you open the firewall's advanced settings?

  1. Press Win + R, type wf.msc and press Enter. You can also run firewall.cpl and click Advanced settings.
  2. The Windows Defender Firewall with Advanced Security window opens. Inbound Rules and Outbound Rules are in the left panel.

How do you block an inbound port, such as Remote Desktop (3389)?

This is a lab example on a test machine. Remote Desktop uses TCP port 3389 by default, and exposing it to the internet is a common cause of attacks, so many organisations block it from untrusted networks.

  1. Click Inbound Rules, then New Rule in the right panel.
  2. Choose Port and click Next.
  3. Select TCP, choose Specific local ports and enter 3389.
  4. Select Block the connection.
  5. Tick the profiles that apply: Domain, Private, Public.
  6. Name the rule Block RDP Inbound and click Finish.

How do you check it works?

From another machine on your lab network, run Remote Desktop Connection (mstsc) to the test PC. It should fail. A better check shows the port state without a full RDP session:

Test-NetConnection -ComputerName 192.168.1.20 -Port 3389

Use your test machine's IP address. TcpTestSucceeded : False means the port is not reachable. Remember, Windows already blocks unsolicited inbound traffic unless an allow rule exists. You need an explicit block rule mainly to override a broader allow rule, or to make your intent visible in the rule list. If you do need Remote Desktop, a safer pattern is to allow it only from a trusted address range or through a VPN rather than from everywhere.

How do you block outbound web traffic (ports 80 and 443)?

Outbound blocking is useful for restricting an application or a test machine, but be careful. Blocking 80 and 443 for the whole machine stops browsers, Windows Update and most cloud services.

  1. Click Outbound Rules, then New Rule.
  2. Choose Port, select TCP and enter 80, 443.
  3. Select Block the connection, choose the profiles, and name it Block Web Outbound.

How do you check it works?

Test-NetConnection -ComputerName www.example.com -Port 443

You should see TcpTestSucceeded : False. A browser should show a connection error. The command ping www.example.com may still reply, because ping uses ICMP, not TCP ports 80 or 443. That is correct behaviour, and it also proves DNS still works. Remove the test rule when you finish.

How do you create the same rules with PowerShell?

PowerShell is faster, repeatable and easier to document. Run it in an elevated window. The cmdlet reference is in Microsoft's New-NetFirewallRule page.

New-NetFirewallRule -DisplayName "Block RDP Inbound" -Direction Inbound -Protocol TCP -LocalPort 3389 -Action Block -Profile Any

New-NetFirewallRule -DisplayName "Block Web Outbound" -Direction Outbound -Protocol TCP -RemotePort 80,443 -Action Block -Profile Any

List and inspect rules:

Get-NetFirewallRule -DisplayName "Block RDP Inbound" | Get-NetFirewallPortFilter
Get-NetFirewallRule -Direction Inbound -Action Block -Enabled True

Disable or delete a rule:

Disable-NetFirewallRule -DisplayName "Block Web Outbound"
Remove-NetFirewallRule -DisplayName "Block Web Outbound"

The older netsh tool still works if you meet it in scripts:

netsh advfirewall firewall add rule name="Block RDP Inbound" dir=in action=block protocol=TCP localport=3389

How do you see which rule is blocking something?

Turn on logging for dropped packets. Then read the log.

Set-NetFirewallProfile -Profile Domain, Private, Public -LogBlocked True -LogMaxSizeKilobytes 4096

By default the log is written to %SystemRoot%\System32\LogFiles\Firewall\pfirewall.log. Each line shows the date, action (DROP or ALLOW), protocol, source and destination addresses, and ports. If your test fails but you do not see a DROP line, the problem is probably not the firewall. Look at routing, DNS, the other machine's firewall or the service itself. Our article on diagnosing firewall and port blocking issues walks through that process.

What if a rule does not work?

  • Check for a conflicting allow rule. Block overrides allow, so an allow rule is not the cause. But a rule on the wrong profile, or one that is disabled, will not apply.
  • Check the active profile. Run Get-NetConnectionProfile. If you are on Private and the rule is for Public only, it does nothing.
  • Check direction and port side. For inbound, the port is the local port. For outbound to a web server, the port is the remote port.
  • Check for third-party security software. It may manage the firewall instead of Windows.
  • Check group policy. On a work PC, domain policy can override local rules.

Best practices for Windows Firewall rules

  1. Name rules so another admin can understand them: what, why, and who requested it.
  2. Prefer allowing specific programs and addresses over opening wide ranges.
  3. Limit scope. Use the Scope tab to restrict a rule to a trusted IP range.
  4. Keep logging on for dropped packets on important machines.
  5. Review rules regularly. Old allow rules from retired software are a risk.
  6. Export your policy before big changes: netsh advfirewall export "C:\backup\firewall.wfw".
  7. Test in a lab or on a non-critical machine first.

To learn which ports services use, see the top 20 common network ports. The same ideas on Linux, with iptables and firewalld, are in our Linux firewall guide.

Next steps

Firewall rules are a core defensive skill for a security analyst. To build it into a career, see WebAsha's Certified Network Defender (CND) course, or start with Computer Network.

Related reading

Frequently Asked Questions

Press Win + R, type wf.msc and press Enter. This opens Windows Defender Firewall with Advanced Security, where Inbound Rules and Outbound Rules are listed. You can also run firewall.cpl and click Advanced settings.

Inbound rules control connections arriving at your computer, such as someone connecting to port 3389. Outbound rules control connections that start from your computer, such as a program connecting to a web server on port 443.

Open wf.msc, choose Inbound or Outbound Rules, click New Rule, select Port, choose TCP or UDP and the port number, select Block the connection, pick the profiles and name the rule. Or use New-NetFirewallRule in PowerShell with -Action Block.

Use Test-NetConnection with the target address and port, for example Test-NetConnection 192.168.1.20 -Port 3389. TcpTestSucceeded False means the port is unreachable. Also check the firewall log, which shows dropped packets.

Yes. In Windows Firewall, when a block rule and an allow rule both match the same traffic, the block rule takes precedence. Rules that are disabled or set for a different network profile do not apply.

Ping uses ICMP, not TCP ports 80 or 443, so it is not affected by those port rules. If ping replies but websites do not load, that suggests the web port block is working and DNS and basic connectivity are fine.

Not on a machine you use normally. Port 443 carries HTTPS, so blocking it stops browsers, Windows Update and most cloud services. Test outbound blocks on a lab VM and scope real rules to a specific program or address.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.