Windows Firewall Configuration - Truly Block EVERYTHING...

Discussion in 'Windows 10' started by CODYQX4, Aug 24, 2015.

  1. shewolf

    shewolf MDL Senior Member

    Joined:
    Apr 16, 2015
    Messages:
    471
    Likes Received:
    1,023
    Trophy Points:
    10
    #141 shewolf, Sep 14, 2015
    Last edited by a moderator: Apr 20, 2017
  2. shewolf

    shewolf MDL Senior Member

    Joined:
    Apr 16, 2015
    Messages:
    471
    Likes Received:
    1,023
    Trophy Points:
    10
    #142 shewolf, Sep 14, 2015
    Last edited: Sep 16, 2015
    auditpol /set /subcategory:"Filtering Platform Connection" /failure:enable > enter
     
  3. Mr.X

    Mr.X MDL Guru

    Joined:
    Jul 14, 2013
    Messages:
    7,625
    Likes Received:
    14,952
    Trophy Points:
    240
    #143 Mr.X, Sep 14, 2015
    Last edited by a moderator: Apr 20, 2017
  4. shewolf

    shewolf MDL Senior Member

    Joined:
    Apr 16, 2015
    Messages:
    471
    Likes Received:
    1,023
    Trophy Points:
    10
    #144 shewolf, Sep 14, 2015
    Last edited: Sep 15, 2015
    --- svchost.exe in one instance check Windows Update in another check Windows Defender update and etc..., this gives rise to another IP.

    --- to know that, you have to use full log as explained above. It is difficult to explain if the other does not take part.
     
  5. shewolf

    shewolf MDL Senior Member

    Joined:
    Apr 16, 2015
    Messages:
    471
    Likes Received:
    1,023
    Trophy Points:
    10
    #145 shewolf, Sep 14, 2015
    Last edited: Sep 16, 2015
    auditpol /set /subcategory:"Filtering Platform Connection" /success:enable > enter
     
  6. freaker

    freaker MDL Novice

    Joined:
    Sep 15, 2015
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    0
    Hello

    I setup my firewall with this guide.

    But cant get internet.

    The wlanstick is blocked. What rule must I set up?
     
  7. Mr.X

    Mr.X MDL Guru

    Joined:
    Jul 14, 2013
    Messages:
    7,625
    Likes Received:
    14,952
    Trophy Points:
    240
    To get internet you need to allow every browser / app you need to access.
     
  8. freaker

    freaker MDL Novice

    Joined:
    Sep 15, 2015
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    0
    Yes i allowed internet explorer for test.
    I connect wlan and i shows the sign with limited.
    If i set to low Filtering wlan connects internet
    and browser works.
     
  9. Mike.mt

    Mike.mt MDL Novice

    Joined:
    Aug 3, 2015
    Messages:
    7
    Likes Received:
    4
    Trophy Points:
    0
    freaker.. if you applied the reg file posted by the OP you will have the very basic rules for internet connectivity. No WIFI, File / Print / Network Sharing etc. The reason that you can get out on Low filtering is that the firewall is letting all outbound requests go through, whilst Medium will only allow the approved rules in the list.


    WFC is a nifty little app & can assist both advanced & novice users. In your case you need to clear & reset your rules back to WFC recommended defaults, delete or block unrequired services / apps. In – Out & add apps & other services not listed that you require. These are per user settings & are not generic rules.

    BR

    Mike
     
  10. yro

    yro MDL Addicted

    Joined:
    Jul 26, 2009
    Messages:
    561
    Likes Received:
    100
    Trophy Points:
    30
    Interesting that it seems this guide for blocking everything works better than a lot of personal firewall out there... Realy interesting. Doing some tests here and all seems to get blocked, all kinds of atacks Im trying get blocked... dont have a proper answer to if this guide can replace personal firewalls, but so far.. so good.
     
  11. Mr.X

    Mr.X MDL Guru

    Joined:
    Jul 14, 2013
    Messages:
    7,625
    Likes Received:
    14,952
    Trophy Points:
    240
    I'm using this solution in Win8.1

    First, I installed Win8.1 with update 3 using an untouched iso (no a single extra update), then implemented this solution and had a lot of svchost.exe activity blocked. I monitored this behavior around 10 days in a row.

    Yesterday I installed all updates up to date via WU and now I have only 12 svchost.exe entries in WFC log after 3 hours running.

    I am :confused: :D
     
  12. LifeIsNotEasy

    LifeIsNotEasy MDL Novice

    Joined:
    Jun 26, 2015
    Messages:
    31
    Likes Received:
    66
    Trophy Points:
    0

    So what is that means ??

    M$ has modified(via WU) their calling-back modules to bypass the firewall so you can not log them anymore :confused:

    just one possibility:D
     
  13. Mr.X

    Mr.X MDL Guru

    Joined:
    Jul 14, 2013
    Messages:
    7,625
    Likes Received:
    14,952
    Trophy Points:
    240
    Exactly my same thoughts, just want to someone else say it out loud lol
     
  14. freaker

    freaker MDL Novice

    Joined:
    Sep 15, 2015
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    0
    Can someone help me with my rules...I deleted the rules i know and no need. But there many more i dont know if it is needed.

    Everything must be blocked.Only Windowsupdate Wifi,LAN and my apps are allowed to go online.

    But i need 20 posts to supply my rules :(
     
  15. Mr.X

    Mr.X MDL Guru

    Joined:
    Jul 14, 2013
    Messages:
    7,625
    Likes Received:
    14,952
    Trophy Points:
    240
    Strangely, today svchost.exe activity back to normal :biggrin:
    Lots of entries in WFC connections log.
    Anyway I keep a Full policy file backup just in case M$ decides to revert firewall ruleset back to its defaults ...
     
  16. CyberUser

    CyberUser MDL Junior Member

    Joined:
    May 15, 2012
    Messages:
    62
    Likes Received:
    42
    Trophy Points:
    0
    Tried the partial policy.wpw ... did not work out for HomeGroup Networking.
    Does anyone know what are the WFC policies or rules to enable local HomeGroup Networking ?:g:
    Thks.
     
  17. Medic

    Medic MDL Novice

    Joined:
    Sep 24, 2011
    Messages:
    19
    Likes Received:
    2
    Trophy Points:
    0
    Thanks for sharing and all the hard work <_>
     
  18. Drexl

    Drexl MDL Junior Member

    Joined:
    Aug 9, 2007
    Messages:
    59
    Likes Received:
    7
    Trophy Points:
    0
    I don't have WFC, but in the standard interface there are two rules for Homegroup in inbound and two in outbound.

    Inbound:

    Svchost.exe - Peer Networking Grouping, remote address: local subnet, protocol: TCP, local port: 3587, remote port: any
    Svchost.exe - Peer Name Resolution Protocol, remote address: local subnet, protocol: UDP, local port: 3540, remote port: any

    The ports are reversed for outbound:

    Svchost.exe - Peer Networking Grouping, remote address: local subnet, protocol: TCP, local port: any, remote port: 3587
    Svchost.exe - Peer Name Resolution Protocol, remote address: local subnet, protocol: UDP, local port: any, remote port: 3540
     
  19. freaker

    freaker MDL Novice

    Joined:
    Sep 15, 2015
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    0
    #159 freaker, Sep 17, 2015
    Last edited: Sep 17, 2015
    i installed all updates for win10 and now i cant open WFC from Taskbar no right & leftklick.

    After deinstalled update for update and testet if it working.

    Removing KB3081455 solved error.

    Anyone have this too?
     
  20. Chriss71

    Chriss71 MDL Member

    Joined:
    Feb 22, 2008
    Messages:
    115
    Likes Received:
    1
    Trophy Points:
    10
    It's a pain in the a$$ to get Updates working with the Whitelist Method. Anyone know all (or the most) Microsoft Update IP's? Is there a list of all known Microsoft IP's?
    Questions over Questions... :g: