Windows Firewall Configuration - Truly Block EVERYTHING...

Discussion in 'Windows 10' started by CODYQX4, Aug 24, 2015.

  1. unknwn

    unknwn MDL Novice

    Jul 29, 2015
    7
    2
    0
    #61 unknwn, Aug 25, 2015
    Last edited: Aug 25, 2015
    For me windows update also didn't work with IP addresses in the op. If you are using windows firewall control, use "connection log feature" in manage rules, filter out blocked attempts. Refresh the log, see the latest attempt (or better just clear the log, so it will be easier to see latest attempts). Then press to update windows, refresh the log, you will see attempts by windows update getting blocked. You can perform this a few times to be sure that the IP's you will get are used for windows update.
    See the screenshot attached.
    Press on a few connections at once and use "customize and create" option to create one rule for these all IPs. Customize the rule as seen in screenshot, just leave IP's as you get.
    You might need to perform that a few times. It seems not all IPs will appear from the first time and Windows Update might work for that time, but not the next.

    Windows firewall allows to block everything, that's how one should do as per OP.
     

    Attached Files:

  2. shewolf

    shewolf MDL Senior Member

    Apr 16, 2015
    471
    1,066
    10
    #62 shewolf, Aug 25, 2015
    Last edited: Aug 25, 2015
    That's right BS-it svchost.exe rule ! Windows update, svchost.exe must be connected with wuauserv service,otherwise you have an open connection to all.
     

    Attached Files:

    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. unknwn

    unknwn MDL Novice

    Jul 29, 2015
    7
    2
    0
    Windows Update doesn't work for me if the rule is connected to wuauserv service.
     
  4. dudedroid

    dudedroid MDL Junior Member

    Apr 28, 2011
    98
    9
    0
    Has anyone tried ZoneAlarm Firewall? In that you can disable all outbound and inbound traffic and then allow everything one by one whenever they try to use the network.
     
  5. murphy78

    murphy78 MDL DISM Enthusiast

    Nov 18, 2012
    7,389
    11,614
    240
    Yes, it's looking like svchost.exe is the way to do it. If I find any further information (which I doubt) I'll add it here.
     
  6. drew84

    drew84 MDL Expert

    Mar 13, 2014
    1,354
    2,308
    60
    Post No. 57 - Thanks for this post shewolf...
    Presumably these changes would show up in the WFC UI and could be ammended from there if need be.
     
  7. shewolf

    shewolf MDL Senior Member

    Apr 16, 2015
    471
    1,066
    10

    I knew, because I told you. Look, Windows Default Firewall Policy has rule svchost|wuauserv and you with 10$ B.S-it piece downgrade your system.
    If you allow all instances of svchost.exe to freely go out to the Internet (in your case it is) you've done a security and privacy hole as big as the moon. :eek:
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  8. shewolf

    shewolf MDL Senior Member

    Apr 16, 2015
    471
    1,066
    10
    #68 shewolf, Aug 26, 2015
    Last edited: Aug 26, 2015
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  9. shewolf

    shewolf MDL Senior Member

    Apr 16, 2015
    471
    1,066
    10
    What you are interested, maybe I know ?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  10. unknwn

    unknwn MDL Novice

    Jul 29, 2015
    7
    2
    0
    #70 unknwn, Aug 26, 2015
    Last edited: Aug 26, 2015
    My Windows 10 didn't have such rule or at least I couldn't find it, can you give a reference? Why you are so unhappy about 10$ software?:biggrin: The software is a free tool which allows for easy monitoring of connections and creating the appropriate rules for them, after rule set is finished software can be ditched.
    Not larger than it is by default.
     
  11. Carol666

    Carol666 MDL Member

    Aug 12, 2015
    129
    10
    10
    I don't have windows firewall where can I find it?
    Upssss I think I have accidently uninstall it and used router to block unwanted traffic
     
  12. shewolf

    shewolf MDL Senior Member

    Apr 16, 2015
    471
    1,066
    10

    If you think so you do not need any reference, you have a "smaller" hole and be happy.:p
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  13. unknwn

    unknwn MDL Novice

    Jul 29, 2015
    7
    2
    0
    #74 unknwn, Aug 26, 2015
    Last edited: Aug 26, 2015
    BTW regarding hidden windows rules - Windows Service Hardening (which also include rules to allow windows defender, indexer and search), will these be overridden by custom user rules to block this traffic? Or the hidden rules will get priority?

    You sound like a troll here. Also I don't have that windows update rule enabled.:biggrin:
     
  14. shewolf

    shewolf MDL Senior Member

    Apr 16, 2015
    471
    1,066
    10

    If this satisfy you, to me it is fine, you've got a problem.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  15. unknwn

    unknwn MDL Novice

    Jul 29, 2015
    7
    2
    0
    #76 unknwn, Aug 26, 2015
    Last edited: Aug 26, 2015
    I would appreciate if could provide a windows firewall rule to allow windows updates working without creating "privacy hole as big as the moon". Also could you elaborate how allowing everything by default with some rules to block search and other exes is safer than block everything with allowing some svchost connections to particular IPs?
    I have checked the logs with my rules and most svchost connections were blocked apart from local ones and IPs that I included.
    With default rules(allow all) and your suggested rules to block search/cortana and etc there will be more svchost traffic going through.

    BTW can anyone elaborate how WSH (Windows Service Hardening) works as per my previous post?
     
  16. abbodi1406

    abbodi1406 MDL KB0000001

    Feb 19, 2011
    16,211
    84,862
    340
    Update Session Orchestrator (Uso) is the one responsible for new WU
    you should allow its service UsoSvc and client usoclient.exe
     
  17. swettylez

    swettylez MDL Novice

    Aug 14, 2015
    4
    1
    0
    Excellent work as ever Cody and fine use of a superb little program.
     
  18. CODYQX4

    CODYQX4 MDL Developer

    Sep 4, 2009
    4,813
    45,775
    150
    #79 CODYQX4, Aug 26, 2015
    Last edited: Apr 12, 2019
    (OP)
    .
     
  19. odiebugs1

    odiebugs1 MDL Expert

    Jul 30, 2015
    1,390
    465
    60
    I hope you don't mind, I linked your post into my post about Activation, it is such a great help to people, thanks for taking the time to give everyone such a great tool. :thumbsup: