Getting to know Windows Firewall

Hello community, the idea of this post is that users can learn and use the Windows 10 Firewall with its features.

Cover.jpeg


We must keep in mind that the use of a Firewall is important, and it is our first line of defense, as it acts as a barrier between our computer and the networks we connect to, allowing or blocking connections according to established rules. This is essential to protect us from cyber threats. As far as I am concerned I have always used in Windows 10 its own firewall with its advanced options.

The first thing to understand is the default behavior of our firewall in Windows 10:

  1. Block all incoming traffic, unless a rule is created where traffic is allowed.
  2. Outbound traffic is allowed, traffic is only blocked if a rule is created that allows this.

Additionally there is the possibility of blocking both incoming and outgoing traffic and creating rules to allow applications to go out to the internet, which is what I do thanks to the advanced options of the Windows firewall.

The second is to understand what firewall rules are:

The firewall rules are going to determine how network traffic is going to be managed by allowing or blocking it according to a series of conditions to make this possible. In Windows 10 a large selection of conditions are offered to achieve this, among which are:

  1. Application, service or program name.
  2. Source and destination IP addresses.
  3. Protocol types and ICMP traffic types.

The third thing to understand is the concept of network profiles used by the Firewall.

Profiles are a feature that allow a lot of flexibility when configuring different scenarios, where different behaviors of our firewall are needed.

For example: We may need to connect to a public network and therefore need the firewall to be more restrictive, but we may also need to be connected to a private network or at home and do not need such a strict behavior. Therefore, we achieve these behaviors depending on the network profiles used by the firewall.

The Windows Firewall has three network profiles to work with, domain, private and public.

Below, I describe the profiles:

Domain network:
The domain network profile is automatically designated to a computer that is joined to
a Domain Controller in Windows. This profile cannot be set manually.

Private Network:
The Private Network profile is created to connect to networks that are trusted.

Public Network:
The Public Network profile is for networks where more security is required.

In the following illustration we can see how to access the Windows 10 firewall, all we have to do is go to the control panel and search for Windows Firewall.

1.jpg



Next a window opens where we can see at a very basic level the main options that Windows offers with its firewall.

Here the firewall status is shown (green active, red deactivated) in my case it is active for each type of network profile such as Domain Networks, Private Networks and Public or Guest Networks.

2.jpg



Next, you can see the option 'Allow Applications to communicate through Window Firewall', where you can easily grant Internet access to the Applications.

3.jpg



When entering and clicking on the Change Configuration button, you can add or change the access rules for each application, and then the window on the left will pop up where we look for the path of the program to allow.

4.jpg



Now we are going to see the options of advanced configurations of the Windows firewall.
Here we click on Advanced Settings.

6.jpg



Below we can see the 'Advanced Configuration' window where all the entry and exit rules are defined.

7.jpg



You can view the default policies for the three network profiles, Domain Profile, Private Profile and Public Profile. Network traffic permissions on the firewall are defined by the profile that is running and the firewall rules associated with the profile.

As I said before the Windows firewall has by default the policy of blocking all incoming traffic and allowing outgoing traffic this can be seen in the Advanced configuration window.

In 'Windows Defender Firewall Properties' you can change (allow or block) incoming and outgoing network traffic. We can also enable or disable the firewall for a selected profile, and other actions can be performed such as detecting protected network connections where it is possible to select the installed network interfaces, configure firewall notifications, and define the path on the hard disk of the logs that our Firewall registers.

8.jpg



In the 'Supervision - Firewall' option you can see all the active rules we have and their detailed configuration.

9.jpg

10.jpg



Working with the Firewall Rules

In the advanced options we have the Inbound Rules and Outbound Rules, here we have the rules that are working. Only those with a green check mark are enabled, the rest are disabled.

If we were to create new rules we should carefully consider where we define them, if we need to allow traffic from outside to our PC, for example, we define it in “Inbound Rules”. And if we need to block some traffic originating from the PC, we do it in “Outbound Rules”.

11.jpg


With the Windows firewall we will be able to create four types of rules:

Program: This Rule allows us to control the connections of a program running on our computer.
Port: rule that controls connections associated with TCP and UDP protocols.
Predefined: You can choose rules already created related to Windows services.
Custom: This is a group of rules that can be created and configured with various parameters.

Now we will see the procedure to create rules in our Firewall.

In order to create new rules, right click on 'Inbound Rules' or 'Outbound Rules' and then on 'New Rule'. As shown in the image.

12.jpg



Then in each case depending on the type of rule we select is to follow the steps in the wizard until the creation of the rule is completed.

This is the end of my explanation, I hope it has been useful to the readers and they have learned something beneficial. On the internet there is information about this that you can read to go deeper into the subject.


I say goodbye, thank you very much for your attention.



-All images used were taken from screenshots of my computer.




You can follow me on my social networks:

Facebook

Linkedin

Twitter



0
0
0.000
5 comments
avatar

Congratulations @rainerlester8308! You have completed the following achievement on the Hive blockchain And have been rewarded with New badge(s)

You received more than 3000 upvotes.
Your next target is to reach 3250 upvotes.

You can view your badges on your board and compare yourself to others in the Ranking
If you no longer want to receive notifications, reply to this comment with the word STOP

Check out our last posts:

LEO Power Up Day - August 15, 2024
0
0
0.000