Windows Firewall
The Windows Firewall policy configuration manages the Windows firewall on managed devices. It consists of three parts: global properties, settings per network profile and individual firewall rules.
At least one of the three parts has to be configured before saving — global properties, a profile or a firewall rule.
Global properties
The global properties apply across profiles to the entire device.
- Certificate revocation list (CRL) verification
- Fail CRL verification on revoked certificate only
- Fail CRL verification on any error encountered
- Pre-shared key encoding
- IPsec exemptions
- Both IPv4 and IPv6 DHCP traffic
- Neighbor discover IPv6 ICMP type-codes
- Router discover IPv6 ICMP type-codes
- Enable packet queuing
- Queue inbound encrypted packets only
- Queue packets after decryption is performed for forwarding only
- Opportunistically match authentication set per keying module
Profile properties
The following settings are configured per network profile — Domain network (workplace network), Private network (discoverable) and Public network (not discoverable):
- Enable firewall
- Allow default action for inbound connections
- Allow default action for outbound connections
- Disable inbound notifications
- Disable stealth mode
- IPsec secured packet exemption with Stealth Mode
- Disable unicast responses to multicast broadcasts
- Block stateful File Transfer Protocol (FTP)
- Allow firewall rules from the local store
- IPsec rules from the local store
- Authorized application firewall rules from the local store
- Global port firewall rules from the local store
Firewall rules
Application, ports and network types can be defined per rule. A maximum of 20 address or port ranges is possible per rule.
- Rule name
- Rule description
- Rule enabled
- Allow connection for this rule
- Traffic direction
- Incoming
- Outgoing
- Full file path
- Package family name
- Windows service
- IP Protocol
- Local port range
- Remote port range
- Local address range
- Remote address range
- Network types
- Interface types
- Local Area Network
- Wireless
- Remote Access
- Edge Traversal setting enabled
- Local user authorization list
Related topics
- VPN → — VPN profiles for Windows devices.
- Custom CSP → — settings that have no dedicated configuration.