Windows Firewall overview - Windows Security (2024)

  • Article
  • Applies to:
    Windows 11, ✅ Windows 10, ✅ Windows Server 2022, ✅ Windows Server 2019, ✅ Windows Server 2016

Windows Firewall is a security feature that helps to protect your device by filtering network traffic that enters and exits your device. This traffic can be filtered based on several criteria, including source and destination IP address, IP protocol, or source and destination port number. Windows Firewall can be configured to block or allow network traffic based on the services and applications that are installed on your device. This allows you to restrict network traffic to only those applications and services that are explicitly allowed to communicate on the network.

Windows Firewall is a host-based firewall that is included with the operating system and enabled by default on all Windows editions.

Windows Firewall supports Internet Protocol security (IPsec), which you can use to require authentication from any device that is attempting to communicate with your device. When authentication is required, devices that can't be authenticated as a trusted device can't communicate with your device. You can use IPsec to require that certain network traffic is encrypted to prevent it from being read by network packet analyzers that could be attached to the network by a malicious user.

Windows Firewall also works with Network Location Awareness so that it can apply security settings appropriate to the types of networks to which the device is connected. For example, Windows Firewall can apply the public network profile when the device is connected a coffee shop wi-fi, and the private network profile when the device is connected to the home network. This allows you to apply more restrictive settings to public networks to help keep your device secure.

Practical applications

Windows Firewall offers several benefits to address your organization's network security challenges:

  • Reduced risk of network security threats: By reducing the attack surface of a device, Windows Firewall provides an additional layer of defense to the defense-in-depth model. This increases manageability and decreases the likelihood of a successful attack
  • Protection of sensitive data and intellectual property: Windows Firewall integrates with IPsec to provide a simple way to enforce authenticated, end-to-end network communications. This allows for scalable, tiered access to trusted network resources, helping to enforce data integrity and, if necessary, protect data confidentiality
  • Extended value of existing investments: Windows Firewall is a host-based firewall included with the operating system, so no additional hardware or software is required. It's also designed to complement existing non-Microsoft network security solutions through a documented API

Windows edition and licensing requirements

The following table lists the Windows editions that support Windows Firewall:

Windows ProWindows EnterpriseWindows Pro Education/SEWindows Education
YesYesYesYes

Windows Firewall license entitlements are granted by the following licenses:

Windows Pro/Pro Education/SEWindows Enterprise E3Windows Enterprise E5Windows Education A3Windows Education A5
YesYesYesYesYes

For more information about Windows licensing, see Windows licensing overview.

Concepts

The default behavior of Windows Firewall is to:

  • block all incoming traffic, unless solicited or matching a rule
  • allow all outgoing traffic, unless matching a rule

Firewall rules

Firewall rules identify allowed or blocked network traffic, and the conditions for this to happen. The rules offer an extensive selection of conditions to identify traffic, including:

  • Application, service or program name
  • Source and destination IP addresses
  • Can make use dynamic values, like default gateway, DHCP servers, DNS servers and local subnets
  • Protocol name or type. For transport layer protocols, TCP and UDP, you can specify ports or port ranges. For custom protocols, you can use a number between 0 and 255 representing the IP protocol
  • Interface type
  • ICMP/ICMPv6 traffic type and code

Firewall profiles

Windows Firewall offers three network profiles: domain, private and public. The network profiles are used to assign rules. For example, you can allow a specific application to communicate on a private network, but not on a public network.

Windows Firewall overview - Windows Security (2) Domain network

The domain network profile is automatically applied to a device that is joined to an Active Directory domain, when it detects the availability of a domain controller. This network profile cannot be set manually.

Tip

Another option to detect the domain network is to configure the policy settings in the NetworkListManager Policy CSP, which applies to Microsoft Entra joined devices too.

Windows Firewall overview - Windows Security (3) Private network

The private network profile is designed for private networks such as a home network. It can be set manually on a network interface by an administrator.

Windows Firewall overview - Windows Security (4) Public network

The public network profile is designed with higher security in mind for public networks, like Wi-Fi hotspots, coffee shops, airports, hotels, etc. It's the default profile for unidentified networks.

Tip

Use the PowerShell cmdlet Get-NetConnectionProfile to retrieve the active network category (NetworkCategory). Use the PowerShell cmdlet Set-NetConnectionProfile to switch the category between private and public.

Next steps

Learn about Windows Firewall rules and design recommendations:

Windows Firewall rules >

Windows Firewall overview - Windows Security (5) Provide feedback

To provide feedback for Windows Firewall, open Feedback Hub (WIN+F) and use the category Security and Privacy > Network protection.

Windows Firewall overview - Windows Security (2024)

FAQs

Windows Firewall overview - Windows Security? ›

Windows Firewall filters the two-way network traffic and protects the local device from unauthorized traffic. It provides you the means to create rules depending on which network traffic will be allowed to access a device and vice versa. The Firewall also supports Internet Protocol security (IPsec).

What is Windows Firewall security? ›

Windows Firewall is a security feature that helps to protect your device by filtering network traffic that enters and exits your device. This traffic can be filtered based on several criteria, including source and destination IP address, IP protocol, or source and destination port number.

How do I enable Windows Firewall on Windows Security? ›

In this article
  1. Go to Start and open Control Panel.
  2. Select System and Security > Windows Defender Firewall.
  3. Choose Turn Windows Defender Firewall on or off.
  4. Select Turn on Windows Defender Firewall for domain, private, and public network settings.
Dec 1, 2023

How do I check my Windows Security? ›

Run a malware scan manually
  1. Select Start > Settings > Update & Security > Windows Security and then Virus & threat protection. Open Windows Security settings.
  2. Under Current threats, select Quick scan (or in early versions of Windows 10, under Threat history, select Scan now).

Is Windows Security firewall good enough? ›

Windows Firewall is effective enough that you may not need a third-party firewall. You use the App & Browser Control page to configure aspects of SmartScreen Filter.

Do I need antivirus if I have Windows Firewall? ›

Firewalls do not eliminate the need for antivirus because the two serve different purposes.

What is the difference between Windows Firewall and Windows Defender? ›

Windows Defender (now Microsoft Defender) is an antivirus program that protects your system from various threats such as malware, viruses, etc. On the other hand, Windows Defender Firewall is responsible for monitoring network traffic and blocking hackers to prevent unauthorized access.

Should Windows Firewall be on or off? ›

It's important to have Microsoft Defender Firewall on, even if you already have another firewall on. It helps protect you from unauthorized access. Select a network profile: Domain network, Private network, or Public network. Under Microsoft Defender Firewall, switch the setting to On.

How do I know if my Windows Firewall is enabled? ›

To check your firewall configuration, open Control Panel and then select 'System and Security. Choose Windows Defender Firewall. Select 'Advanced Settings'. Opening the Advanced Settings, you will need to review the 'Inbound Rules'.

How to see what Windows Firewall is blocking? ›

To see if your firewall is blocking a website, app, or port on Windows, go to Windows Firewall > Advanced Settings and check your Outbound rules.

How do I activate Windows Security? ›

To enable Windows Defender
  1. Click the windows logo. ...
  2. Scroll down and click Windows Security to open the application.
  3. On the Windows Security screen, check if any antivirus program has been installed and running in your computer. ...
  4. Click on Virus & threat protection as shown.
  5. Next, select Virus & threat protection icon.

How do I open my Windows Security? ›

Open the Windows Security app by clicking the shield icon in the task bar or searching the Start menu for Defender. Click on the Virus & threat protection tile (or the shield icon on the left menu bar).

Why can't i view Windows Security? ›

You can try the following steps to resolve the issue: Run the Windows Security Troubleshooter: Go to Settings > Update & Security > Troubleshoot. Find and run the Windows Security troubleshooter. Reset Windows Security app: Go to Settings > Apps > Apps & features.

Is Windows Firewall as good as McAfee? ›

While McAfee does offer additional features such as firewall protection and identity theft protection, Windows Defender has been shown to be effective at detecting and removing viruses and malware.

Are Windows Defender and Windows Security the same thing? ›

What Is Windows Defender? Microsoft Defender Antivirus is an antivirus program included in Windows Security, which is built into Windows 10 and 11 operating systems and doesn't require a separate paid subscription.

Do I need antivirus if I have Windows Defender? ›

However, for Macs, Windows and Androids, antivirus software is a necessity, as new viruses are created every day. Do you really need antivirus for Windows 10? You do need an antivirus for Windows 10, even though it comes with Microsoft Defender Antivirus.

Should I keep Windows Firewall on or off? ›

It's important to have Microsoft Defender Firewall on, even if you already have another firewall on. It helps protect you from unauthorized access. Select a network profile: Domain network, Private network, or Public network. Under Microsoft Defender Firewall, switch the setting to On.

What will happen if Windows Firewall is off? ›

When a user turns the Windows Firewall off, the extra layer or barrier is no longer there. Hackers can have unrestricted access to data, which may result in data breaches. The worst thing that could happen is a total network collapse. This issue occurs if the system does not have enough protection.

How do I turn off Windows Security firewall? ›

Turning off the Windows firewall
  1. Select Start > Control Panel > System and Security > Windows Firewall. ...
  2. Select Turn Windows Firewall on or off. ...
  3. Select Turn off Windows Firewall (not recommended) for both Home or work (private) network location settings and Public network location settings, and then click OK.

Top Articles
How to Stop Using Credit Cards - Penny Pinchin' Mom
5 Things to Give Up to Get out of Debt - The Million Dollar Mama
New Slayer Boss - The Araxyte
What are Dietary Reference Intakes?
THE 10 BEST River Retreats for 2024/2025
Xrarse
CSC error CS0006: Metadata file 'SonarAnalyzer.dll' could not be found
Delectable Birthday Dyes
Lonadine
Conan Exiles Thrall Master Build: Best Attributes, Armor, Skills, More
Missed Connections Dayton Ohio
iLuv Aud Click: Tragbarer Wi-Fi-Lautsprecher für Amazons Alexa - Portable Echo Alternative
Moviesda3.Com
Swedestats
Hocus Pocus Showtimes Near Amstar Cinema 16 - Macon
Self-Service ATMs: Accessibility, Limits, & Features
Tips on How to Make Dutch Friends & Cultural Norms
Greenville Sc Greyhound
Lexus Credit Card Login
Discord Nuker Bot Invite
Plost Dental
Kroger Feed Login
Labcorp.leavepro.com
Tactical Masters Price Guide
Lawrence Ks Police Scanner
Used Safari Condo Alto R1723 For Sale
Los Amigos Taquería Kalona Menu
What Is Xfinity and How Is It Different from Comcast?
Tamil Play.com
Roto-Rooter Plumbing and Drain Service hiring General Manager in Cincinnati Metropolitan Area | LinkedIn
Chilangos Hillsborough Nj
Eleceed Mangaowl
Hisense Ht5021Kp Manual
Hannibal Mo Craigslist Pets
The Syracuse Journal-Democrat from Syracuse, Nebraska
Dmitri Wartranslated
Ticket To Paradise Showtimes Near Marshall 6 Theatre
The Banshees Of Inisherin Showtimes Near Reading Cinemas Town Square
Final Jeopardy July 25 2023
Wasmo Link Telegram
Weather Underground Cedar Rapids
Acts 16 Nkjv
Miami Vice turns 40: A look back at the iconic series
Smite Builds Season 9
Blackwolf Run Pro Shop
Dr Mayy Deadrick Paradise Valley
Coffee County Tag Office Douglas Ga
UT Announces Physician Assistant Medicine Program
Breaking down the Stafford trade
Nope 123Movies Full
Doelpuntenteller Robert Mühren eindigt op 38: "Afsluiten in stijl toch?"
Kidcheck Login
Latest Posts
Article information

Author: Madonna Wisozk

Last Updated:

Views: 5979

Rating: 4.8 / 5 (68 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Madonna Wisozk

Birthday: 2001-02-23

Address: 656 Gerhold Summit, Sidneyberg, FL 78179-2512

Phone: +6742282696652

Job: Customer Banking Liaison

Hobby: Flower arranging, Yo-yoing, Tai chi, Rowing, Macrame, Urban exploration, Knife making

Introduction: My name is Madonna Wisozk, I am a attractive, healthy, thoughtful, faithful, open, vivacious, zany person who loves writing and wants to share my knowledge and understanding with you.