Manage Windows Firewall from the command line
More actions
Inspect, enable, troubleshoot and temporarily disable Windows Defender Firewall from PowerShell or the current netsh advfirewall context.
netsh firewall set opmode command is from the older firewall context and has been replaced by netsh advfirewall and the NetSecurity PowerShell module.Check firewall state
PowerShell:
Get-NetFirewallProfile
Command Prompt:
netsh advfirewall show allprofiles state
Enable the firewall
PowerShell:
Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled True
Command Prompt:
netsh advfirewall set allprofiles state on
Add a scoped allow rule
For example, allow inbound HTTPS:
New-NetFirewallRule -DisplayName "Allow HTTPS" -Direction Inbound -Protocol TCP -LocalPort 443 -Action Allow
Use the required profiles, interfaces, programs or remote-address scope for the actual deployment rather than creating a broader rule than necessary.
Temporarily disable firewall profiles
Microsoft supports disabling the profiles while leaving the Windows Firewall service running.
PowerShell:
Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled False
Command Prompt:
netsh advfirewall set allprofiles state off
Re-enable them immediately after the troubleshooting test:
Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled True
Export the firewall policy
Before broader troubleshooting changes, the current firewall policy can be exported:
netsh advfirewall export "C:\Temp\firewall-backup.wfw"
What changed from the legacy article
The previous Tech-Wiki page used:
netsh firewall set opmode mode=disable profile=all
Microsoft's current command-line documentation uses the netsh advfirewall context or the PowerShell NetSecurity cmdlets instead.