Windows Advanced Firewall Programmatic Access


on11

Ninja
Local time
8:13 AM
Posts
6
Location
Area 51.2
OS
Windows 11 Pro
I finally got around to creating and account here as two of my daily drivers are now Windows 11. So yay me :)

As a developer I know that we can create Windows Firewall rules, exceptions and so on programmatically. From the perspective of convenience having a program create the rule for you is I suppose great, but from a malicious perspective I don't like that any program can add or modify my rules as they want to suit themselves.

I wanted to know if there is a way to "disable" programmatic access to the Windows Firewall basically making it so that unless you create the rule yourself through the GUI or command line, they cannot be created automatically programmatically. I have searched for this and the only thing you get back is how to disable the firewall which is not what I need.

Before the customary deluge of why don't you use a third party firewall and having all kinds of suggestion to use Comodo or other things thrown as a response, please save it. I already use that, this is a particular use case and I am not interested in "another program" as a solution, just a native way within Windows, policy, registry or whatnot, to disable the programmatic access. I am hoping for the community's insights.

Thanks in advance.
 
Windows Build/Version
Version 22H2 (Build 22621.2283)

My Computers My Computers

  • At a glance

    Windows 11 ProIntel Core i7-9750H @ 2.60 GHz, 6 Cores, 12 L...16 GBNVIDIA GeForce GTX 1650
    OS
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Dell XPS 15 7590
    CPU
    Intel Core i7-9750H @ 2.60 GHz, 6 Cores, 12 Logical
    Motherboard
    Intel
    Memory
    16 GB
    Graphics Card(s)
    NVIDIA GeForce GTX 1650
    Sound Card
    Realtek / Intel Display Audio / Grind Fuel
    Monitor(s) Displays
    Dell SHP 148A
    Screen Resolution
    1920 x 1080 x 59 hertz
    Hard Drives
    NVMe PC601 SK, 500 GB
    Keyboard
    Standard 101/102-Key
    Mouse
    Synaptics Touchpad / Logi MX Anywhere 3
    Internet Speed
    500 Mbps
    Browser
    Edge / Firefox
    Antivirus
    Defender
    Other Info
    Goodix Fingerprint
  • At a glance

    Windows 11 Pro11th Generation Core i7-1185G7 @ 3.00 GHz, 4 ...64 GBNVIDIA T500
    Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    HP ZBook Firefly 15.6 inch G8 Mobile Workstation
    CPU
    11th Generation Core i7-1185G7 @ 3.00 GHz, 4 Cores, 8 Logical
    Motherboard
    Intel
    Memory
    64 GB
    Graphics card(s)
    NVIDIA T500
    Sound Card
    Realtek / Intel Smart Sound / TOZO-NC9 Plus
    Monitor(s) Displays
    Intel Iris Xe
    Screen Resolution
    3840 x 2160 x 60 hertz
    Hard Drives
    NVMe Samsung MZVLB2T0HALB-000H1, 2 TB
    Keyboard
    Standard 101/102-Key
    Mouse
    Synaptics Touchpad / PointStyk / Logi MX Anywhere 3
    Internet Speed
    500 Mbps
    Browser
    Edge / Firefox
    Antivirus
    Defender
    Other Info
    Synaptics FS7605 Touch Fingerprint Sensor with PurePoint
I don't believe there's a GPO policy to lock out Firewall rule changes.

The best answer is to export your current (and verified) ruleset to .vfw, and import them back as a Group Policy. Because it's now treated as policy, you can use "gpupdate /force" to revert any changes. Using the MPSSVC event logs, it's possible to track recent changes to Firewall that were made outside of the Group Policy.

 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
I don't believe there's a GPO policy to lock out Firewall rule changes.

The best answer is to export your current (and verified) ruleset to .vfw, and import them back as a Group Policy. Because it's now treated as policy, you can use "gpupdate /force" to revert any changes. Using the MPSSVC event logs, it's possible to track recent changes to Firewall that were made outside of the Group Policy.


It is certainly disappointing but thank you for the alternative option. At least gives me something to work out. I always wished there was a way to create the rules and assign them to groups so they can be disabled and enabled en mass but with script on load to ensure the rules are always exactly what we want but seems despite showing the group in the GUI there is actually no option to set it, but that's a different issue. Thank you again.
 

My Computers My Computers

  • At a glance

    Windows 11 ProIntel Core i7-9750H @ 2.60 GHz, 6 Cores, 12 L...16 GBNVIDIA GeForce GTX 1650
    OS
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Dell XPS 15 7590
    CPU
    Intel Core i7-9750H @ 2.60 GHz, 6 Cores, 12 Logical
    Motherboard
    Intel
    Memory
    16 GB
    Graphics Card(s)
    NVIDIA GeForce GTX 1650
    Sound Card
    Realtek / Intel Display Audio / Grind Fuel
    Monitor(s) Displays
    Dell SHP 148A
    Screen Resolution
    1920 x 1080 x 59 hertz
    Hard Drives
    NVMe PC601 SK, 500 GB
    Keyboard
    Standard 101/102-Key
    Mouse
    Synaptics Touchpad / Logi MX Anywhere 3
    Internet Speed
    500 Mbps
    Browser
    Edge / Firefox
    Antivirus
    Defender
    Other Info
    Goodix Fingerprint
  • At a glance

    Windows 11 Pro11th Generation Core i7-1185G7 @ 3.00 GHz, 4 ...64 GBNVIDIA T500
    Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    HP ZBook Firefly 15.6 inch G8 Mobile Workstation
    CPU
    11th Generation Core i7-1185G7 @ 3.00 GHz, 4 Cores, 8 Logical
    Motherboard
    Intel
    Memory
    64 GB
    Graphics card(s)
    NVIDIA T500
    Sound Card
    Realtek / Intel Smart Sound / TOZO-NC9 Plus
    Monitor(s) Displays
    Intel Iris Xe
    Screen Resolution
    3840 x 2160 x 60 hertz
    Hard Drives
    NVMe Samsung MZVLB2T0HALB-000H1, 2 TB
    Keyboard
    Standard 101/102-Key
    Mouse
    Synaptics Touchpad / PointStyk / Logi MX Anywhere 3
    Internet Speed
    500 Mbps
    Browser
    Edge / Firefox
    Antivirus
    Defender
    Other Info
    Synaptics FS7605 Touch Fingerprint Sensor with PurePoint
Someone shared the idea of adding a group name tag in front of every rule's name, to better identify them. Then you could use regular expressions to process them.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Someone shared the idea of adding a group name tag in front of every rule's name, to better identify them. Then you could use regular expressions to process them.
Aha, clever. Currently we tag them [Application_Name] for sorting and identification; but thinking your RegEx idea can grab this existing piece of data, nice. Thank you.
 

My Computers My Computers

  • At a glance

    Windows 11 ProIntel Core i7-9750H @ 2.60 GHz, 6 Cores, 12 L...16 GBNVIDIA GeForce GTX 1650
    OS
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Dell XPS 15 7590
    CPU
    Intel Core i7-9750H @ 2.60 GHz, 6 Cores, 12 Logical
    Motherboard
    Intel
    Memory
    16 GB
    Graphics Card(s)
    NVIDIA GeForce GTX 1650
    Sound Card
    Realtek / Intel Display Audio / Grind Fuel
    Monitor(s) Displays
    Dell SHP 148A
    Screen Resolution
    1920 x 1080 x 59 hertz
    Hard Drives
    NVMe PC601 SK, 500 GB
    Keyboard
    Standard 101/102-Key
    Mouse
    Synaptics Touchpad / Logi MX Anywhere 3
    Internet Speed
    500 Mbps
    Browser
    Edge / Firefox
    Antivirus
    Defender
    Other Info
    Goodix Fingerprint
  • At a glance

    Windows 11 Pro11th Generation Core i7-1185G7 @ 3.00 GHz, 4 ...64 GBNVIDIA T500
    Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    HP ZBook Firefly 15.6 inch G8 Mobile Workstation
    CPU
    11th Generation Core i7-1185G7 @ 3.00 GHz, 4 Cores, 8 Logical
    Motherboard
    Intel
    Memory
    64 GB
    Graphics card(s)
    NVIDIA T500
    Sound Card
    Realtek / Intel Smart Sound / TOZO-NC9 Plus
    Monitor(s) Displays
    Intel Iris Xe
    Screen Resolution
    3840 x 2160 x 60 hertz
    Hard Drives
    NVMe Samsung MZVLB2T0HALB-000H1, 2 TB
    Keyboard
    Standard 101/102-Key
    Mouse
    Synaptics Touchpad / PointStyk / Logi MX Anywhere 3
    Internet Speed
    500 Mbps
    Browser
    Edge / Firefox
    Antivirus
    Defender
    Other Info
    Synaptics FS7605 Touch Fingerprint Sensor with PurePoint
Welcome binary or should I say 011000111000111 !!
 

My Computers My Computers

  • At a glance

    Win 11 x 64 HomeAMD Ryzen 5 7600 6-Core ProcessorDDR 5. 32GB (2 x16GB)GeForce RTX 5060i
    OS
    Win 11 x 64 Home
    Computer type
    PC/Desktop
    Manufacturer/Model
    pc specialists build (updated various times)
    CPU
    AMD Ryzen 5 7600 6-Core Processor
    Motherboard
    Gigabyte Technology Co., Ltd. Product:B650M K
    Memory
    DDR 5. 32GB (2 x16GB)
    Graphics Card(s)
    GeForce RTX 5060i
    Sound Card
    2 channel HD Audio + Mic/Hphone jack
    Monitor(s) Displays
    coolermaster 27 inch
    Screen Resolution
    1920 x 1080
    Hard Drives
    three external 3TBs, 4 TBs and 5tb. (Storage) Samsung SSD 970 (C).
    Case
    Coolermaster
    Cooling
    internal fans
    Keyboard
    Logi K270 & Logitech gamer G213
    Mouse
    M310 and Logi Gamer G203
    Internet Speed
    530.85mbps download. 52.70 upload
    Browser
    Opera, Vivaldi, Chrome & Firefox
    Antivirus
    Kaspersky Premium
    Other Info
    Build: 26100.ge_release 240331-1435
  • At a glance

    Android
    Operating System
    Android
    Computer type
    Tablet
    Manufacturer/Model
    Samsung
    Keyboard
    logi K270, when in use.
    Mouse
    Logi M220
    Internet Speed
    500
    Browser
    Opera.Edge. Chrome.Vivaldi
    Antivirus
    Kaspersky Premium
Welcome binary or should I say 011000111000111 !!
Thank you. Lurked for a long time on the Ten Forum before registering. Here I was hoping credentials would transfer, didn't, so took me a bit to sign up here, but glad to be here.
 

My Computers My Computers

  • At a glance

    Windows 11 ProIntel Core i7-9750H @ 2.60 GHz, 6 Cores, 12 L...16 GBNVIDIA GeForce GTX 1650
    OS
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Dell XPS 15 7590
    CPU
    Intel Core i7-9750H @ 2.60 GHz, 6 Cores, 12 Logical
    Motherboard
    Intel
    Memory
    16 GB
    Graphics Card(s)
    NVIDIA GeForce GTX 1650
    Sound Card
    Realtek / Intel Display Audio / Grind Fuel
    Monitor(s) Displays
    Dell SHP 148A
    Screen Resolution
    1920 x 1080 x 59 hertz
    Hard Drives
    NVMe PC601 SK, 500 GB
    Keyboard
    Standard 101/102-Key
    Mouse
    Synaptics Touchpad / Logi MX Anywhere 3
    Internet Speed
    500 Mbps
    Browser
    Edge / Firefox
    Antivirus
    Defender
    Other Info
    Goodix Fingerprint
  • At a glance

    Windows 11 Pro11th Generation Core i7-1185G7 @ 3.00 GHz, 4 ...64 GBNVIDIA T500
    Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    HP ZBook Firefly 15.6 inch G8 Mobile Workstation
    CPU
    11th Generation Core i7-1185G7 @ 3.00 GHz, 4 Cores, 8 Logical
    Motherboard
    Intel
    Memory
    64 GB
    Graphics card(s)
    NVIDIA T500
    Sound Card
    Realtek / Intel Smart Sound / TOZO-NC9 Plus
    Monitor(s) Displays
    Intel Iris Xe
    Screen Resolution
    3840 x 2160 x 60 hertz
    Hard Drives
    NVMe Samsung MZVLB2T0HALB-000H1, 2 TB
    Keyboard
    Standard 101/102-Key
    Mouse
    Synaptics Touchpad / PointStyk / Logi MX Anywhere 3
    Internet Speed
    500 Mbps
    Browser
    Edge / Firefox
    Antivirus
    Defender
    Other Info
    Synaptics FS7605 Touch Fingerprint Sensor with PurePoint

Latest Support Threads

Back
Top Bottom