Windows Firewall

The Windows Firewall policy configuration manages the Windows firewall on managed devices. It consists of three parts: global properties, settings per network profile and individual firewall rules.


Global properties

The global properties apply across profiles to the entire device.

  • Certificate revocation list (CRL) verification
  • Fail CRL verification on revoked certificate only
  • Fail CRL verification on any error encountered
  • Pre-shared key encoding
  • IPsec exemptions
  • Both IPv4 and IPv6 DHCP traffic
  • Neighbor discover IPv6 ICMP type-codes
  • Router discover IPv6 ICMP type-codes
  • Enable packet queuing
  • Queue inbound encrypted packets only
  • Queue packets after decryption is performed for forwarding only
  • Opportunistically match authentication set per keying module

Profile properties

The following settings are configured per network profile — Domain network (workplace network), Private network (discoverable) and Public network (not discoverable):

  • Enable firewall
  • Allow default action for inbound connections
  • Allow default action for outbound connections
  • Disable inbound notifications
  • Disable stealth mode
  • IPsec secured packet exemption with Stealth Mode
  • Disable unicast responses to multicast broadcasts
  • Block stateful File Transfer Protocol (FTP)
  • Allow firewall rules from the local store
  • IPsec rules from the local store
  • Authorized application firewall rules from the local store
  • Global port firewall rules from the local store

Firewall rules

Application, ports and network types can be defined per rule. A maximum of 20 address or port ranges is possible per rule.

  • Rule name
  • Rule description
  • Rule enabled
  • Allow connection for this rule
  • Traffic direction
  • Incoming
  • Outgoing
  • Full file path
  • Package family name
  • Windows service
  • IP Protocol
  • Local port range
  • Remote port range
  • Local address range
  • Remote address range
  • Network types
  • Interface types
  • Local Area Network
  • Wireless
  • Remote Access
  • Edge Traversal setting enabled
  • Local user authorization list

  • VPN → — VPN profiles for Windows devices.
  • Custom CSP → — settings that have no dedicated configuration.
Top