Windows Firewall Configuration - Truly Block EVERYTHING...

Discussion in 'Windows 10' started by CODYQX4, Aug 24, 2015.

  1. fccard

    fccard MDL Novice

    Jun 6, 2011
    6
    1
    0
    Hello.
    Does anyone have an updated rule that allows windows update for the new windows 10 1803 version that can share with me, please?
    I tried the one posted from the op on the first page but it is blocking windows update to check for them.
    Thanks in advance.
     
  2. 13dk13

    13dk13 MDL Novice

    Feb 11, 2011
    41
    12
    0
    im sad that wfc cant manage icmp rules or custom rules from that :( time to move

    just looking around just notice are only icmpv6 rules to pack too big but not the variant of icmpv4 mmm anyone know why ipv4 pretty sure its most use still
     
  3. TairikuOkami

    TairikuOkami MDL Expert

    Mar 15, 2014
    1,172
    1,055
    60
    ICMP is required by IPv6, but it is only optional for IPv4, I block it.
     
  4. M07REX

    M07REX MDL Novice

    Jan 30, 2017
    25
    10
    0
    Seems like such thing is common nowadays. Probably we should thank Google for making every competing tech giant there to be a "software as a service"
    Even Steam/Valve is jumping to the action with different games, some paid for and some free, from different developers and publishers, sneak up this "Red Shell" thing which is basically Windows 10 Telemetry but even more shameless in promoting it (basically we, Red Shell, will gather all the data about you while playing in order to measure current trends and giving the data to publishers and developers muehehehehe).

    If there is other choice, some people said "use Linux use Linux wululululululululululu" but Linux and FOSS/GNU future is bleak due to how increasingly secluded, unfriendly, and hostile toward today's network approach Richard Stallman is, how most software moved from GNU to crowdfunding, freemium, and "proprietary freeware", even less people willingly wrote software for price of TOTALLY FREE AND OPEN SOURCE. Otherwise use the overpriced Macbook therefore become a corporate whale, and even then they are pressured by the FBI just because a suspect is using their product and FBI needs decryption.
     
  5. Thomas Dubreuil

    Thomas Dubreuil MDL Senior Member

    Aug 29, 2017
    363
    620
    10
    #266 Thomas Dubreuil, Nov 21, 2018
    Last edited: May 22, 2019
    Windows Update ips are country dependent, and will also change randomly.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  6. W7U

    W7U MDL Junior Member

    Feb 19, 2017
    57
    11
    0
    Based on the comments by @Pyr3x and @M07REX, I cannot tell which is real and which is merely a conspiracy theory.

    I know that telemetry is objectionable by many, but going as far as to hunt down people using cracked software? This is confusing me and may cause some people to be more paranoid than the reality.

    I would in my opinion leave out the rhetoric and focus on how to disable telemetry entirely.
     
  7. zdyesportt

    zdyesportt MDL Novice

    Dec 17, 2016
    3
    0
    0
    Thanks CODY,Brilliant work.
     
  8. Thomas Dubreuil

    Thomas Dubreuil MDL Senior Member

    Aug 29, 2017
    363
    620
    10
    #269 Thomas Dubreuil, Dec 22, 2018
    Last edited: Mar 19, 2019
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  9. ZERO269

    ZERO269 MDL Novice

    Apr 10, 2016
    14
    2
    0
    Excellent tool... I'll try playing with this in a Virtual Machine first. Thanks for all your hard work CodyQZ4
     
  10. MyDigitalName

    MyDigitalName MDL Member

    Sep 12, 2009
    124
    17
    10
    Hi all,
    the first post seem to be gone, just a dot there.
    I am looking for a bare set of rules that enables Windows Update and the MS Store but nothing else.
    Preferable, importable via WFC.
    Thanks!
     
  11. Thomas Dubreuil

    Thomas Dubreuil MDL Senior Member

    Aug 29, 2017
    363
    620
    10
    #272 Thomas Dubreuil, May 22, 2019
    Last edited: May 22, 2019
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  12. ozaki1

    ozaki1 MDL Novice

    May 18, 2017
    13
    0
    0
    Anyone know why the post got edited ?
     
  13. MonarchX

    MonarchX MDL Expert

    May 5, 2007
    1,732
    313
    60
    Yeah, re-up the post, please!
     
  14. pinkfufu

    pinkfufu MDL Novice

    May 20, 2011
    45
    5
    0
    What's happened to Cody's posts here? All I see is a single period where I imagine there should be text.
     
  15. Carlos Detweiller

    Carlos Detweiller Emperor of Ice-Cream

    Dec 21, 2012
    6,358
    7,077
    210
    He left and deleted his posts.
     
  16. pinkfufu

    pinkfufu MDL Novice

    May 20, 2011
    45
    5
    0
    That's a shame.
     
  17. pinkfufu

    pinkfufu MDL Novice

    May 20, 2011
    45
    5
    0
    1. What is referred to by |App=System| here?
    2. How can the rule "CoreNet-IPv6-Out"="v2.24|Action=Allow|Active=TRUE|Dir=Out|Protocol=41|App=System|Name=@FirewallAPI.dll,-25352|Desc=@FirewallAPI.dll,-25358|EmbedCtxt=@FirewallAPI.dll,-25000|" be applied outside of Windows Firewall? How can an equivalent firewall rule be created in, for example, Symantec Endpoint Protection?

    Thanks.
     
  18. Thomas Dubreuil

    Thomas Dubreuil MDL Senior Member

    Aug 29, 2017
    363
    620
    10
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  19. pinkfufu

    pinkfufu MDL Novice

    May 20, 2011
    45
    5
    0
    Many thanks for an such a detailed and informative post. Will be using some of this.

    Still have a question...

    I want to create the rule "CoreNet-IPv6-Out"="v2.24|Action=Allow|Active=TRUE|Dir=Out|Protocol=41|App=System|Name=@FirewallAPI.dll,-25352|Desc=@FirewallAPI.dll,-25358|EmbedCtxt=@FirewallAPI.dll,-25000|" in Symantec Endpoint Protection.

    What is the "System" referred to in the preceding rule? There is no "System" in SEP; is there an equivalent to "System" in SEP?

    TIA