MYTHOSAI

Windows security / PRACTICAL GUIDE

Check Windows Firewall profiles and rules

Confirm the active profile and inspect rules before changing or disabling anything.

Before you start

Windows PowerShell; administrator access for rule changes.

Separate profile from application

Windows Firewall has Domain, Private and Public profiles. The current network classification determines which profile rules apply. A rule allowing an application on a Private network may not apply on a Public network. Diagnose that mismatch rather than disabling the whole firewall.

Inspect the current state

powershell
Get-NetConnectionProfile | Select-Object InterfaceAlias,
  NetworkCategory, IPv4Connectivity
Get-NetFirewallProfile | Select-Object Name, Enabled,
  DefaultInboundAction, DefaultOutboundAction

The second query reports all profiles, not just the one currently used. On a business device, policy may control the effective configuration.

Examine enabled inbound rules

powershell
Get-NetFirewallRule -PolicyStore ActiveStore |
  Where-Object {
    $_.Enabled -eq 'True' -and $_.Direction -eq 'Inbound'
  } | Select-Object DisplayName, Action, Profile

Use Windows Defender Firewall with Advanced Security for a detailed view. For a rule of interest, inspect its programme or service, local port, protocol and permitted remote addresses. A display name is only a label; it does not prove what the rule actually permits.

Diagnose an application connection

  1. Confirm the application is running and listening on the expected address and port.
  2. Confirm the source computer can route to that address.
  3. Identify the effective firewall profile and relevant rule.
  4. If a rule change is necessary, limit it to the required programme, port and trusted source range. Keep a record of the change and rollback method.

Do not treat a successful ping as proof that a TCP service is reachable. Ping and the service use different protocols or rule paths.

Verify safely

Test the intended connection from an authorised client. Also test that an unrelated source remains blocked where the design requires it. If the change is temporary, remove it after troubleshooting. On centrally managed devices, ask the administrator to implement the approved policy instead of adding a conflicting local workaround.

Common mistakes

Switching an untrusted network to Private just to make sharing work broadens exposure. An Any programme, Any port, Any remote address rule is rarely a precise fix. A firewall does not replace authentication or patching, and local success does not prove internet reachability.

Keep the firewall on

The useful outcome is a narrow working rule with the firewall enabled. If an application requires disabling the firewall, stop and investigate the actual connectivity requirements before accepting that configuration.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.