Query Windows Firewall

Rising Flight 4,756 Reputation points
2024-12-20T22:16:38.5333333+00:00

Hi All,

I currently have Windows Firewall disabled in my environment, but I plan to enable it. If I enable Windows Firewall, what inbound and outbound traffic or ports are blocked or allowed by default?For example, let’s say I enable Windows Firewall on Server01, which has an application installed on it, and Server02 is unable to access the application. What logs can I check on Server01 to determine which traffic is hitting it and which ports are being blocked? Additionally, I have a third-party antivirus solution running on my servers. Is it a good approach to enable Windows Firewall alongside this antivirus solution? Please guide me.

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,849 questions
Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,548 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,486 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,875 questions
Windows Server Infrastructure
Windows Server Infrastructure
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Infrastructure: A Microsoft solution area focused on providing organizations with a cloud solution that supports their real-world needs and meets evolving regulatory requirements.
558 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Yanhong Liu 13,835 Reputation points Microsoft Vendor
    2024-12-27T01:48:44.0233333+00:00

    Hello,

    Thank you for posting in Q&A forum.

    By default, Windows Firewall blocks most inbound connections unless there are rules allowing specific traffic. Outbound traffic is typically allowed unless explicitly blocked by rules.

    Default Inbound and Outbound Traffic

    1. Inbound Traffic:
      • By default, most inbound traffic is blocked. However, there are some exceptions for essential system services and pre-defined rules, such as allowing remote desktop connections if it is enabled in system settings.
    2. Outbound Traffic:
      • Outbound traffic is generally allowed unless there are specific rules configured to block it.

    Troubleshooting Blocked Traffic

    If Server02 cannot access an application on Server01 after enabling Windows Firewall, you can use the following methods and logs to determine which traffic is being blocked:

    1. Windows Firewall Logs:
      • You can enable logging for Windows Firewall to capture dropped packets and successful connections.
      • To enable logging:
        • Open Windows Defender Firewall with Advanced Security.
        • Right-click on Windows Defender Firewall with Advanced Security on Local Computer, then click Properties.
        • Go to the Logging tab.
        • Configure the Log dropped packets and Log successful connections options.
      The default log file location is: C:\Windows\System32\LogFiles\Firewall\pfirewall.log
    2. Event Viewer:
      • You can also check the Event Viewer for firewall-related events.
        • Open Event Viewer.
        • Navigate to Applications and Services Logs > Microsoft > Windows > Windows Firewall with Advanced Security > Firewall.

    Enabling Windows Firewall with Third-Party Antivirus

    It is generally a good approach to enable Windows Firewall alongside a third-party antivirus solution. Here are some points to consider:

    1. Compatibility:
      • Make sure that the third-party antivirus solution is compatible with Windows Firewall. Most modern antivirus solutions should be able to coexist with Windows Firewall without issues.
    2. Avoid Conflicting Rules:
      • Check the firewall rules and settings in both your antivirus solution and Windows Firewall to ensure that they do not conflict with each other. Sometimes, antivirus solutions come with their own firewall, and you should decide whether to use one or the other, but not both.
    3. Security Enhancement:
      • Using both can enhance your security posture, as each may cover different aspects of network security and provide layered defense.

    I hope the information above is helpful.

    Best Regards,

    Yanhong Liu

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.