Windows Firewall Configuration - Truly Block EVERYTHING...

Discussion in 'Windows 10' started by CODYQX4, Aug 24, 2015.

  1. shewolf

    shewolf MDL Senior Member

    Apr 16, 2015
    471
    1,071
    10
    #141 shewolf, Sep 14, 2015
    Last edited by a moderator: Apr 20, 2017
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  2. shewolf

    shewolf MDL Senior Member

    Apr 16, 2015
    471
    1,071
    10
    #142 shewolf, Sep 14, 2015
    Last edited: Sep 16, 2015
    auditpol /set /subcategory:"Filtering Platform Connection" /failure:enable > enter
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. Mr.X

    Mr.X MDL Guru

    Jul 14, 2013
    8,556
    15,642
    270
    #143 Mr.X, Sep 14, 2015
    Last edited by a moderator: Apr 20, 2017
  4. shewolf

    shewolf MDL Senior Member

    Apr 16, 2015
    471
    1,071
    10
    #144 shewolf, Sep 14, 2015
    Last edited: Sep 15, 2015
    --- svchost.exe in one instance check Windows Update in another check Windows Defender update and etc..., this gives rise to another IP.

    --- to know that, you have to use full log as explained above. It is difficult to explain if the other does not take part.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  5. shewolf

    shewolf MDL Senior Member

    Apr 16, 2015
    471
    1,071
    10
    #145 shewolf, Sep 14, 2015
    Last edited: Sep 16, 2015
    auditpol /set /subcategory:"Filtering Platform Connection" /success:enable > enter
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  6. freaker

    freaker MDL Novice

    Sep 15, 2015
    4
    0
    0
    Hello

    I setup my firewall with this guide.

    But cant get internet.

    The wlanstick is blocked. What rule must I set up?
     
  7. Mr.X

    Mr.X MDL Guru

    Jul 14, 2013
    8,556
    15,642
    270
    To get internet you need to allow every browser / app you need to access.
     
  8. freaker

    freaker MDL Novice

    Sep 15, 2015
    4
    0
    0
    Yes i allowed internet explorer for test.
    I connect wlan and i shows the sign with limited.
    If i set to low Filtering wlan connects internet
    and browser works.
     
  9. Mike.mt

    Mike.mt MDL Novice

    Aug 3, 2015
    7
    4
    0
    freaker.. if you applied the reg file posted by the OP you will have the very basic rules for internet connectivity. No WIFI, File / Print / Network Sharing etc. The reason that you can get out on Low filtering is that the firewall is letting all outbound requests go through, whilst Medium will only allow the approved rules in the list.


    WFC is a nifty little app & can assist both advanced & novice users. In your case you need to clear & reset your rules back to WFC recommended defaults, delete or block unrequired services / apps. In – Out & add apps & other services not listed that you require. These are per user settings & are not generic rules.

    BR

    Mike
     
  10. yro

    yro MDL Addicted

    Jul 26, 2009
    641
    126
    30
    Interesting that it seems this guide for blocking everything works better than a lot of personal firewall out there... Realy interesting. Doing some tests here and all seems to get blocked, all kinds of atacks Im trying get blocked... dont have a proper answer to if this guide can replace personal firewalls, but so far.. so good.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  11. Mr.X

    Mr.X MDL Guru

    Jul 14, 2013
    8,556
    15,642
    270
    I'm using this solution in Win8.1

    First, I installed Win8.1 with update 3 using an untouched iso (no a single extra update), then implemented this solution and had a lot of svchost.exe activity blocked. I monitored this behavior around 10 days in a row.

    Yesterday I installed all updates up to date via WU and now I have only 12 svchost.exe entries in WFC log after 3 hours running.

    I am :confused: :D
     
  12. LifeIsNotEasy

    LifeIsNotEasy MDL Novice

    Jun 26, 2015
    39
    77
    0

    So what is that means ??

    M$ has modified(via WU) their calling-back modules to bypass the firewall so you can not log them anymore :confused:

    just one possibility:D
     
  13. Mr.X

    Mr.X MDL Guru

    Jul 14, 2013
    8,556
    15,642
    270
    Exactly my same thoughts, just want to someone else say it out loud lol
     
  14. freaker

    freaker MDL Novice

    Sep 15, 2015
    4
    0
    0
    Can someone help me with my rules...I deleted the rules i know and no need. But there many more i dont know if it is needed.

    Everything must be blocked.Only Windowsupdate Wifi,LAN and my apps are allowed to go online.

    But i need 20 posts to supply my rules :(
     
  15. Mr.X

    Mr.X MDL Guru

    Jul 14, 2013
    8,556
    15,642
    270
    Strangely, today svchost.exe activity back to normal :biggrin:
    Lots of entries in WFC connections log.
    Anyway I keep a Full policy file backup just in case M$ decides to revert firewall ruleset back to its defaults ...
     
  16. CyberUser

    CyberUser MDL Junior Member

    May 15, 2012
    63
    42
    0
    Tried the partial policy.wpw ... did not work out for HomeGroup Networking.
    Does anyone know what are the WFC policies or rules to enable local HomeGroup Networking ?:g:
    Thks.
     
  17. Medic

    Medic MDL Novice

    Sep 24, 2011
    19
    2
    0
    Thanks for sharing and all the hard work <_>
     
  18. Drexl

    Drexl MDL Junior Member

    Aug 9, 2007
    59
    7
    0
    I don't have WFC, but in the standard interface there are two rules for Homegroup in inbound and two in outbound.

    Inbound:

    Svchost.exe - Peer Networking Grouping, remote address: local subnet, protocol: TCP, local port: 3587, remote port: any
    Svchost.exe - Peer Name Resolution Protocol, remote address: local subnet, protocol: UDP, local port: 3540, remote port: any

    The ports are reversed for outbound:

    Svchost.exe - Peer Networking Grouping, remote address: local subnet, protocol: TCP, local port: any, remote port: 3587
    Svchost.exe - Peer Name Resolution Protocol, remote address: local subnet, protocol: UDP, local port: any, remote port: 3540
     
  19. freaker

    freaker MDL Novice

    Sep 15, 2015
    4
    0
    0
    #159 freaker, Sep 17, 2015
    Last edited: Sep 17, 2015
    i installed all updates for win10 and now i cant open WFC from Taskbar no right & leftklick.

    After deinstalled update for update and testet if it working.

    Removing KB3081455 solved error.

    Anyone have this too?
     
  20. Chriss71

    Chriss71 MDL Member

    Feb 22, 2008
    115
    1
    10
    It's a pain in the a$$ to get Updates working with the Whitelist Method. Anyone know all (or the most) Microsoft Update IP's? Is there a list of all known Microsoft IP's?
    Questions over Questions... :g: