Windows Firewall Guide: Configure Inbound and Outbound Rules and Test Them in Real Time
Windows Firewall is a crucial security feature that controls network traffic using Inbound and Outbound rules. This guide covers how to configure firewall rules, block or allow network traffic, and verify whether the rules are working using real-time testing methods such as ping, netstat, and telnet. You'll learn how to: Create Inbound Rules (e.g., block Remote Desktop on Port 3389) Create Outbound Rules (e.g., block internet access on Ports 80 and 443) Verify Firewall Rules using command-line tools Modify or remove rules for troubleshooting By following this step-by-step guide, you can enhance network security and ensure that only authorized traffic flows through your system.
Quick answer: To create a Windows Firewall rule, open Windows Defender Firewall with Advanced Security (run wf.msc), choose Inbound Rules or Outbound Rules, click New Rule, pick Port, enter the protocol and port, select Allow or Block, choose the profiles, and name it. Test with Test-NetConnection. Block rules override allow rules, so check for conflicts.
Key takeaways
- Inbound rules control traffic coming to your PC. Outbound rules control traffic leaving it.
- By default Windows blocks unsolicited inbound traffic and allows outbound. You mostly add allow rules inbound and block rules outbound.
- If a block rule and an allow rule both match, the block rule wins.
- Test every rule from another machine, or with
Test-NetConnection, so you know it works instead of assuming. - Practise on a virtual machine. A wrong outbound block can cut off Windows Update, DNS or your remote session.
What are inbound and outbound firewall rules?
A firewall decides which network traffic may pass, based on rules. Windows Defender Firewall with Advanced Security gives each rule a direction, a protocol, ports, programs and an action.
| Direction | Controls | Typical use |
|---|---|---|
| Inbound | Connections arriving at this computer | Allow a web server on port 443, block Remote Desktop on port 3389 |
| Outbound | Connections starting from this computer | Stop an application from calling out, block a risky port |
Each rule also applies to one or more network profiles: Domain, Private and Public. Choose the profiles deliberately. A rule for a coffee-shop Wi-Fi laptop may need to be stricter on Public than at the office on Domain. Microsoft documents the firewall in its Windows Firewall documentation.
How do you open the firewall's advanced settings?
- Press Win + R, type
wf.mscand press Enter. You can also runfirewall.cpland click Advanced settings. - The Windows Defender Firewall with Advanced Security window opens. Inbound Rules and Outbound Rules are in the left panel.
How do you block an inbound port, such as Remote Desktop (3389)?
This is a lab example on a test machine. Remote Desktop uses TCP port 3389 by default, and exposing it to the internet is a common cause of attacks, so many organisations block it from untrusted networks.
- Click Inbound Rules, then New Rule in the right panel.
- Choose Port and click Next.
- Select TCP, choose Specific local ports and enter
3389. - Select Block the connection.
- Tick the profiles that apply: Domain, Private, Public.
- Name the rule
Block RDP Inboundand click Finish.
How do you check it works?
From another machine on your lab network, run Remote Desktop Connection (mstsc) to the test PC. It should fail. A better check shows the port state without a full RDP session:
Test-NetConnection -ComputerName 192.168.1.20 -Port 3389
Use your test machine's IP address. TcpTestSucceeded : False means the port is not reachable. Remember, Windows already blocks unsolicited inbound traffic unless an allow rule exists. You need an explicit block rule mainly to override a broader allow rule, or to make your intent visible in the rule list. If you do need Remote Desktop, a safer pattern is to allow it only from a trusted address range or through a VPN rather than from everywhere.
How do you block outbound web traffic (ports 80 and 443)?
Outbound blocking is useful for restricting an application or a test machine, but be careful. Blocking 80 and 443 for the whole machine stops browsers, Windows Update and most cloud services.
- Click Outbound Rules, then New Rule.
- Choose Port, select TCP and enter
80, 443. - Select Block the connection, choose the profiles, and name it
Block Web Outbound.
How do you check it works?
Test-NetConnection -ComputerName www.example.com -Port 443
You should see TcpTestSucceeded : False. A browser should show a connection error. The command ping www.example.com may still reply, because ping uses ICMP, not TCP ports 80 or 443. That is correct behaviour, and it also proves DNS still works. Remove the test rule when you finish.
How do you create the same rules with PowerShell?
PowerShell is faster, repeatable and easier to document. Run it in an elevated window. The cmdlet reference is in Microsoft's New-NetFirewallRule page.
New-NetFirewallRule -DisplayName "Block RDP Inbound" -Direction Inbound -Protocol TCP -LocalPort 3389 -Action Block -Profile Any
New-NetFirewallRule -DisplayName "Block Web Outbound" -Direction Outbound -Protocol TCP -RemotePort 80,443 -Action Block -Profile Any
List and inspect rules:
Get-NetFirewallRule -DisplayName "Block RDP Inbound" | Get-NetFirewallPortFilter
Get-NetFirewallRule -Direction Inbound -Action Block -Enabled True
Disable or delete a rule:
Disable-NetFirewallRule -DisplayName "Block Web Outbound"
Remove-NetFirewallRule -DisplayName "Block Web Outbound"
The older netsh tool still works if you meet it in scripts:
netsh advfirewall firewall add rule name="Block RDP Inbound" dir=in action=block protocol=TCP localport=3389
How do you see which rule is blocking something?
Turn on logging for dropped packets. Then read the log.
Set-NetFirewallProfile -Profile Domain, Private, Public -LogBlocked True -LogMaxSizeKilobytes 4096
By default the log is written to %SystemRoot%\System32\LogFiles\Firewall\pfirewall.log. Each line shows the date, action (DROP or ALLOW), protocol, source and destination addresses, and ports. If your test fails but you do not see a DROP line, the problem is probably not the firewall. Look at routing, DNS, the other machine's firewall or the service itself. Our article on diagnosing firewall and port blocking issues walks through that process.
What if a rule does not work?
- Check for a conflicting allow rule. Block overrides allow, so an allow rule is not the cause. But a rule on the wrong profile, or one that is disabled, will not apply.
- Check the active profile. Run
Get-NetConnectionProfile. If you are on Private and the rule is for Public only, it does nothing. - Check direction and port side. For inbound, the port is the local port. For outbound to a web server, the port is the remote port.
- Check for third-party security software. It may manage the firewall instead of Windows.
- Check group policy. On a work PC, domain policy can override local rules.
Best practices for Windows Firewall rules
- Name rules so another admin can understand them: what, why, and who requested it.
- Prefer allowing specific programs and addresses over opening wide ranges.
- Limit scope. Use the Scope tab to restrict a rule to a trusted IP range.
- Keep logging on for dropped packets on important machines.
- Review rules regularly. Old allow rules from retired software are a risk.
- Export your policy before big changes:
netsh advfirewall export "C:\backup\firewall.wfw". - Test in a lab or on a non-critical machine first.
To learn which ports services use, see the top 20 common network ports. The same ideas on Linux, with iptables and firewalld, are in our Linux firewall guide.
Next steps
Firewall rules are a core defensive skill for a security analyst. To build it into a career, see WebAsha's Certified Network Defender (CND) course, or start with Computer Network.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0