ESC

Start typing to search across invoices, services, domains, tickets, and more...

Search... Ctrl+K
Windows Server

How to Open and Close Ports in Windows Firewall (GUI and PowerShell)

7 steps 14 min read 1 views 0
On this page

When a website, database, game server or custom application on your Windows VPS cannot be reached from the internet, the usual culprit is a closed port in Windows Firewall. This guide shows how to open and close ports in Windows Firewall on Windows Server 2016/2019/2022 using both the GUI and PowerShell (New-NetFirewallRule / Remove-NetFirewallRule), how to restrict a port to specific source IPs, allow ping, check that a port is listening and test it from outside.

Step 1: Open a Port in Windows Firewall with the GUI

Connect via Remote Desktop, press Win+R and run the command below to open Windows Defender Firewall with Advanced Security. Click Inbound Rules, then New Rule, choose Port, select TCP or UDP and enter the specific local ports (for example 8080 or 80,443). Choose Allow the connection, keep Domain, Private and Public ticked and give the rule a descriptive name.

wf.msc
Outbound traffic is allowed by default, so in most cases you only need inbound rules. Use clear names such as "Allow TCP 8080 - API" so the rule is easy to find when you want to close the port later.

Step 2: Open Ports with PowerShell New-NetFirewallRule

In an elevated PowerShell window a single command opens a port, which is ideal for scripts and repeated deployments. -LocalPort accepts a single port, a comma-separated list or a range, and -Protocol can be TCP or UDP.

# Allow inbound TCP 8080 (all profiles)
New-NetFirewallRule -DisplayName "Allow TCP 8080" -Direction Inbound -Protocol TCP -LocalPort 8080 -Action Allow -Profile Any

# Several ports / a range, and UDP
New-NetFirewallRule -DisplayName "Allow Web 80,443" -Direction Inbound -Protocol TCP -LocalPort 80,443 -Action Allow
New-NetFirewallRule -DisplayName "Allow UDP 27015-27020" -Direction Inbound -Protocol UDP -LocalPort 27015-27020 -Action Allow

Step 3: Restrict a Firewall Port to Specific Source IPs

Database ports (1433, 3306) and management ports should not be open to the whole internet. Add -RemoteAddress with the IPs or subnets you trust; everything else is dropped by the default inbound policy. To change the allowed sources later, edit the rule with Set-NetFirewallRule instead of recreating it.

# Only allow SQL Server 1433 from your office IP and one subnet
New-NetFirewallRule -DisplayName "MSSQL from office" -Direction Inbound -Protocol TCP -LocalPort 1433 -RemoteAddress 203.0.113.10,198.51.100.0/24 -Action Allow

# Change the source list of an existing rule later
Set-NetFirewallRule -DisplayName "MSSQL from office" -RemoteAddress 203.0.113.10,203.0.113.20

Step 4: Close a Port in Windows Firewall (Disable or Remove-NetFirewallRule)

You can close a port by disabling the rule temporarily, deleting it with Remove-NetFirewallRule, or creating an explicit Block rule. In Windows Firewall a Block rule always overrides an Allow rule, so a Block rule is the safest way to guarantee a port stays closed.

# List the rules you created
Get-NetFirewallRule -Direction Inbound | Where-Object DisplayName -like "Allow*" | Format-Table DisplayName,Enabled,Action

# Temporarily disable, or delete permanently
Disable-NetFirewallRule -DisplayName "Allow TCP 8080"
Remove-NetFirewallRule -DisplayName "Allow TCP 8080"

# Explicitly block a port (Block rules win over Allow rules)
New-NetFirewallRule -DisplayName "Block TCP 445" -Direction Inbound -Protocol TCP -LocalPort 445 -Action Block
Never delete or block the Remote Desktop rule (port 3389 or your custom RDP port). Doing so disconnects your session immediately and locks you out.

Step 5: Allow Ping (ICMP) on Windows Server

Windows Server ignores ping by default. This does not affect websites, but monitoring tools and latency tests may report the server as down. The rules below only allow ICMP Echo Request and leave other ICMP types blocked.

# Allow ping (ICMPv4 Echo Request) and ICMPv6 echo
New-NetFirewallRule -DisplayName "Allow ICMPv4 Ping" -Direction Inbound -Protocol ICMPv4 -IcmpType 8 -Action Allow
New-NetFirewallRule -DisplayName "Allow ICMPv6 Ping" -Direction Inbound -Protocol ICMPv6 -IcmpType 128 -Action Allow

# Same with the classic netsh syntax
netsh advfirewall firewall add rule name="Allow ICMPv4 Ping" dir=in action=allow protocol=icmpv4:8,any

Step 6: Check That the Port Is Listening

A firewall rule is useless if no program listens on the port. Use netstat or Get-NetTCPConnection to see the listening address and process ID. If the address is 127.0.0.1, the application only accepts local connections and must be configured to bind to 0.0.0.0 or the server's public IP.

netstat -ano | findstr :8080

Get-NetTCPConnection -State Listen -LocalPort 8080 | Select-Object LocalAddress,LocalPort,OwningProcess
Get-Process -Id (Get-NetTCPConnection -State Listen -LocalPort 8080).OwningProcess

Step 7: Test the Open Port from Outside

Always test from a different computer; testing on the server itself bypasses the firewall and gives misleading results. TcpTestSucceeded : True, or "succeeded" from nc, means the port is reachable.

# From another Windows machine
Test-NetConnection 203.0.113.50 -Port 8080

# From a Linux / macOS machine
nc -zv 203.0.113.50 8080
ping 203.0.113.50

FAQ

I added a firewall rule but the port is still closed. Why?

Check that the program is listening (Step 6), that it is not bound to 127.0.0.1, that no Block rule covers the same port, that you are testing the right protocol (TCP vs UDP) and that your own network does not filter the port. Our "Windows network troubleshooting" guide covers further checks.

Can I simply turn Windows Firewall off?

We do not recommend it. Disabling the firewall exposes SMB, RPC and other system services to internet scanners. Keep it on and open only the ports you need.

Do I need a firewall rule after changing the RDP port?

Yes. Allow the new port first, then restart the Remote Desktop service. See our "change the Windows RDP port" guide for the full procedure.

Still stuck after following these steps? Open a support ticket and the IMIDC 24/7 technical team will help. Please include the server IP, OS version, the commands you ran and a screenshot of the error so we can pinpoint the issue faster.

Was this answer helpful?

Related Tutorials