The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Inspect profilesGet-NetFirewallProfile | Select-Object Name, Enabled, DefaultInboundAction, DefaultOutboundActionView examples
List active enabled rulesGet-NetFirewallRule -PolicyStore ActiveStore -Enabled ` TrueView examples
Get one ruleGet-NetFirewallRule -Name 'CmdMemo-HTTPS-In'View examples
Inspect portsGet-NetFirewallRule -Name 'CmdMemo-HTTPS-In' | Get-NetFirewallPortFilterView examples
Inspect addressesGet-NetFirewallRule -Name 'CmdMemo-HTTPS-In' | Get-NetFirewallAddressFilterView examples
Inspect program scopeGet-NetFirewallRule -Name 'CmdMemo-HTTPS-In' | Get-NetFirewallApplicationFilterView examples
Preview an inbound ruleNew-NetFirewallRule -Name 'CmdMemo-HTTPS-In' ` -DisplayName 'CmdMemo HTTPS' -Direction Inbound ` -Action Allow -Protocol TCP -LocalPort 443 -Profile ` Domain -WhatIfView examples
Preview disablingDisable-NetFirewallRule -Name 'CmdMemo-HTTPS-In' -WhatIfView examples
Preview enablingEnable-NetFirewallRule -Name 'CmdMemo-HTTPS-In' -WhatIfView examples
Preview removalRemove-NetFirewallRule -Name 'CmdMemo-HTTPS-In' -WhatIfView examples
Export firewall policynetsh advfirewall export 'C:\Backup\firewall.wfw'View examples
Test a TCP endpointTest-NetConnection -ComputerName 'server01' -Port 443 ` -InformationLevel DetailedView examples
Inspect profile loggingGet-NetFirewallProfile | Select-Object Name, LogAllowed, LogBlocked, LogFileNameView examples

Windows Defender Firewall evaluates rules from multiple policy stores, profiles, directions, programs, services, addresses, protocols, and ports. Inspect the effective ActiveStore and associated filter objects before changing anything, create narrowly named rules with WhatIf, and preserve an alternate management path before modifying remote access.

Step by step

Detailed examples

01

Inspect effective policy and active network profiles

Profile selection follows network classification, and more than one profile can be active. ActiveStore merges local and group policy. A rule's source and precedence matter; local edits may be ignored where policy disallows local rules. Never solve a specific issue by turning off an entire profile.

Profile and policy baseline
Get-NetConnectionProfile | Select-Object InterfaceAlias, NetworkCategory
Get-NetFirewallProfile | Select-Object Name, Enabled, DefaultInboundAction, DefaultOutboundAction
Get-NetFirewallRule -PolicyStore ActiveStore -Enabled True | Group-Object Direction, Action
Back to quick reference ↑
02

Join rules to their one-to-one filter objects

Get-NetFirewallRule does not display common port, address, program, interface, service, and security conditions directly. Pipe the exact rule to corresponding Get-NetFirewall filter cmdlets. Use Name as a stable identity because DisplayName can be localized and need not be unique.

Complete rule view
$rule = Get-NetFirewallRule -Name 'CmdMemo-HTTPS-In'
$rule | Format-List Name, DisplayName, Enabled, Direction, Action, Profile, PolicyStoreSource
$rule | Get-NetFirewallPortFilter
$rule | Get-NetFirewallAddressFilter
$rule | Get-NetFirewallApplicationFilter
Back to quick reference ↑
03

Scope allowances by every available condition

Direction, action, profile, protocol, port, program, address, and service jointly determine exposure. Use WhatIf, a stable Name, description, and owning group. A broad allow can override expected isolation; a block rule can affect emergency management.

Preview a domain-only application rule
$params = @{
  Name = 'CmdMemo-HTTPS-In'; DisplayName = 'CmdMemo HTTPS inbound'
  Description = 'Approved service endpoint'; Direction = 'Inbound'; Action = 'Allow'
  Profile = 'Domain'; Protocol = 'TCP'; LocalPort = 443
  Program = 'C:\Program Files\CmdMemo\server.exe'; RemoteAddress = 'LocalSubnet'
}
New-NetFirewallRule @params -WhatIf
Back to quick reference ↑
04

Prefer disable before delete and capture recovery state

Disable is reversible and preserves definition metadata while testing impact. Export policy before coordinated local changes, but understand domain policy will reapply and an import can replace policy broadly. Remove only an exact rule after checking ownership and source.

Capture and preview containment
New-Item -ItemType Directory -Path 'C:\Backup' -Force | Out-Null
netsh advfirewall export 'C:\Backup\firewall-before.wfw'
Disable-NetFirewallRule -Name 'CmdMemo-HTTPS-In' -WhatIf
Remove-NetFirewallRule -Name 'CmdMemo-HTTPS-In' -WhatIf
Back to quick reference ↑
05

Test from the correct side and inspect logs

A local listening socket does not prove remote reachability, and Test-NetConnection failure does not alone prove the firewall caused it. Test from an authorized client in the intended network/profile, confirm service listening and route, then correlate allowed or blocked logs.

Correlate listener, client test, and logging
Get-NetTCPConnection -LocalPort 443 -State Listen
Test-NetConnection -ComputerName 'server01' -Port 443 -InformationLevel Detailed
Get-NetFirewallProfile | Select-Object Name, LogAllowed, LogBlocked, LogFileName
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. MicrosoftNetSecurity Modulelearn.microsoft.com
  2. MicrosoftGet-NetFirewallRulelearn.microsoft.com
  3. MicrosoftNew-NetFirewallRulelearn.microsoft.com
  4. MicrosoftWindows Firewall toolslearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback