Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Manage Windows Firewall from the command line

From Tech-Wiki


Inspect, enable, troubleshoot and temporarily disable Windows Defender Firewall from PowerShell or the current netsh advfirewall context.

ⓘ
Validation status
Reviewed against current Microsoft Windows Firewall command-line documentation on 27 September 2026. The original netsh firewall set opmode command is from the older firewall context and has been replaced by netsh advfirewall and the NetSecurity PowerShell module.
!
Prefer a scoped rule to disabling the firewall
If an application or port is being blocked, create or test an appropriately scoped firewall rule where possible. Disabling all firewall profiles removes host firewall filtering and should be limited to controlled troubleshooting.

Check firewall state

PowerShell:

>_Show firewall profiles
Get-NetFirewallProfile

Command Prompt:

>_Show all profile state
netsh advfirewall show allprofiles state

Enable the firewall

PowerShell:

>_Enable Domain, Private and Public profiles
Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled True

Command Prompt:

>_Enable all profiles with netsh
netsh advfirewall set allprofiles state on

Add a scoped allow rule

For example, allow inbound HTTPS:

>_PowerShell example
New-NetFirewallRule -DisplayName "Allow HTTPS" -Direction Inbound -Protocol TCP -LocalPort 443 -Action Allow

Use the required profiles, interfaces, programs or remote-address scope for the actual deployment rather than creating a broader rule than necessary.

Temporarily disable firewall profiles

Microsoft supports disabling the profiles while leaving the Windows Firewall service running.

PowerShell:

>_Temporarily disable all profiles
Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled False

Command Prompt:

>_Temporarily disable all profiles with netsh
netsh advfirewall set allprofiles state off

Re-enable them immediately after the troubleshooting test:

>_Re-enable all profiles
Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled True
!
Do not stop the firewall services as a troubleshooting method
Microsoft states that stopping the Windows Firewall service is unsupported and can cause operating-system and application problems. If the firewall must be disabled for a controlled test, disable the firewall profiles and leave the service running.

Export the firewall policy

Before broader troubleshooting changes, the current firewall policy can be exported:

>_Export Windows Firewall policy
netsh advfirewall export "C:\Temp\firewall-backup.wfw"

What changed from the legacy article

The previous Tech-Wiki page used:

netsh firewall set opmode mode=disable profile=all

Microsoft's current command-line documentation uses the netsh advfirewall context or the PowerShell NetSecurity cmdlets instead.

Official references

See also