Start typing to search across invoices, services, domains, tickets, and more...
When a website, database, game server or custom application on your Windows VPS cannot be reached from the internet, the usual culprit is a closed port in Windows Firewall. This guide shows how to open and close ports in Windows Firewall on Windows Server 2016/2019/2022 using both the GUI and PowerShell (New-NetFirewallRule / Remove-NetFirewallRule), how to restrict a port to specific source IPs, allow ping, check that a port is listening and test it from outside.
Connect via Remote Desktop, press Win+R and run the command below to open Windows Defender Firewall with Advanced Security. Click Inbound Rules, then New Rule, choose Port, select TCP or UDP and enter the specific local ports (for example 8080 or 80,443). Choose Allow the connection, keep Domain, Private and Public ticked and give the rule a descriptive name.
wf.mscIn an elevated PowerShell window a single command opens a port, which is ideal for scripts and repeated deployments. -LocalPort accepts a single port, a comma-separated list or a range, and -Protocol can be TCP or UDP.
# Allow inbound TCP 8080 (all profiles)
New-NetFirewallRule -DisplayName "Allow TCP 8080" -Direction Inbound -Protocol TCP -LocalPort 8080 -Action Allow -Profile Any
# Several ports / a range, and UDP
New-NetFirewallRule -DisplayName "Allow Web 80,443" -Direction Inbound -Protocol TCP -LocalPort 80,443 -Action Allow
New-NetFirewallRule -DisplayName "Allow UDP 27015-27020" -Direction Inbound -Protocol UDP -LocalPort 27015-27020 -Action AllowDatabase ports (1433, 3306) and management ports should not be open to the whole internet. Add -RemoteAddress with the IPs or subnets you trust; everything else is dropped by the default inbound policy. To change the allowed sources later, edit the rule with Set-NetFirewallRule instead of recreating it.
# Only allow SQL Server 1433 from your office IP and one subnet
New-NetFirewallRule -DisplayName "MSSQL from office" -Direction Inbound -Protocol TCP -LocalPort 1433 -RemoteAddress 203.0.113.10,198.51.100.0/24 -Action Allow
# Change the source list of an existing rule later
Set-NetFirewallRule -DisplayName "MSSQL from office" -RemoteAddress 203.0.113.10,203.0.113.20You can close a port by disabling the rule temporarily, deleting it with Remove-NetFirewallRule, or creating an explicit Block rule. In Windows Firewall a Block rule always overrides an Allow rule, so a Block rule is the safest way to guarantee a port stays closed.
# List the rules you created
Get-NetFirewallRule -Direction Inbound | Where-Object DisplayName -like "Allow*" | Format-Table DisplayName,Enabled,Action
# Temporarily disable, or delete permanently
Disable-NetFirewallRule -DisplayName "Allow TCP 8080"
Remove-NetFirewallRule -DisplayName "Allow TCP 8080"
# Explicitly block a port (Block rules win over Allow rules)
New-NetFirewallRule -DisplayName "Block TCP 445" -Direction Inbound -Protocol TCP -LocalPort 445 -Action BlockWindows Server ignores ping by default. This does not affect websites, but monitoring tools and latency tests may report the server as down. The rules below only allow ICMP Echo Request and leave other ICMP types blocked.
# Allow ping (ICMPv4 Echo Request) and ICMPv6 echo
New-NetFirewallRule -DisplayName "Allow ICMPv4 Ping" -Direction Inbound -Protocol ICMPv4 -IcmpType 8 -Action Allow
New-NetFirewallRule -DisplayName "Allow ICMPv6 Ping" -Direction Inbound -Protocol ICMPv6 -IcmpType 128 -Action Allow
# Same with the classic netsh syntax
netsh advfirewall firewall add rule name="Allow ICMPv4 Ping" dir=in action=allow protocol=icmpv4:8,anyA firewall rule is useless if no program listens on the port. Use netstat or Get-NetTCPConnection to see the listening address and process ID. If the address is 127.0.0.1, the application only accepts local connections and must be configured to bind to 0.0.0.0 or the server's public IP.
netstat -ano | findstr :8080
Get-NetTCPConnection -State Listen -LocalPort 8080 | Select-Object LocalAddress,LocalPort,OwningProcess
Get-Process -Id (Get-NetTCPConnection -State Listen -LocalPort 8080).OwningProcessAlways test from a different computer; testing on the server itself bypasses the firewall and gives misleading results. TcpTestSucceeded : True, or "succeeded" from nc, means the port is reachable.
# From another Windows machine
Test-NetConnection 203.0.113.50 -Port 8080
# From a Linux / macOS machine
nc -zv 203.0.113.50 8080
ping 203.0.113.50Check that the program is listening (Step 6), that it is not bound to 127.0.0.1, that no Block rule covers the same port, that you are testing the right protocol (TCP vs UDP) and that your own network does not filter the port. Our "Windows network troubleshooting" guide covers further checks.
We do not recommend it. Disabling the firewall exposes SMB, RPC and other system services to internet scanners. Keep it on and open only the ports you need.
Yes. Allow the new port first, then restart the Remote Desktop service. See our "change the Windows RDP port" guide for the full procedure.
Still stuck after following these steps? Open a support ticket and the IMIDC 24/7 technical team will help. Please include the server IP, OS version, the commands you ran and a screenshot of the error so we can pinpoint the issue faster.