{"id":801,"date":"2026-10-10T09:00:00","date_gmt":"2026-10-10T09:00:00","guid":{"rendered":"https:\/\/vpslake.com\/blog\/?p=801"},"modified":"2026-10-10T09:00:00","modified_gmt":"2026-10-10T09:00:00","slug":"allow-port-firewall-windows-server-2016","status":"publish","type":"post","link":"https:\/\/vpslake.com\/blog\/2026\/10\/10\/allow-port-firewall-windows-server-2016\/","title":{"rendered":"Allow a Port in Windows Server 2016 Firewall"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">To allow port in firewall on Windows Server 2016, create a narrowly defined inbound rule for the service&#8217;s TCP or UDP port. This guide covers the graphical console and PowerShell, then verifies the rule from another computer in about ten minutes.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Prerequisites<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>A VPS running Windows Server 2016 with the service or application you want to expose.<\/li>\n\n\n<li>An active RDP session and a local administrator account, or another account that can open an elevated PowerShell window.<\/li>\n\n\n<li>The exact port number and protocol: TCP and UDP are separate rules. The application must also be configured to listen on that port.<\/li>\n\n\n<li>The server&#8217;s network profile and the source addresses that should be allowed. Limiting the remote address is safer than exposing a management port to the entire internet.<\/li>\n\n\n<li>A Windows RDP server from <a href=\"https:\/\/vpslake.com\/buy-windows-rdp\">VPSLake<\/a> if you need a Windows Server environment for this task.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Step 1: Identify the port, protocol, and listener<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The firewall only filters traffic; it cannot make an application accept connections, so check the service before changing network policy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Open <strong>Windows PowerShell<\/strong> as an administrator and replace <code>8443<\/code> with the port used by your service:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$Port = 8443\nGet-NetTCPConnection -LocalPort $Port -State Listen -ErrorAction SilentlyContinue\nGet-NetUDPEndpoint -LocalPort $Port -ErrorAction SilentlyContinue<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For a TCP service, a result with <code>State<\/code> set to <code>Listen<\/code> confirms that a process has opened the port. No result means you must start or reconfigure the application first. Use the UDP command for a UDP service; UDP has no TCP-style listening handshake.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Expected TCP output resembles this:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>LocalAddress LocalPort RemoteAddress RemotePort State  OwningProcess\n------------ --------- ------------- ---------- ------ -------------\n0.0.0.0      8443      0.0.0.0       0          Listen 4120<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">Step 2: Check the active firewall profile<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Windows applies rules according to the current network profile, so confirm the firewall is enabled without turning it off to troubleshoot.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Get-NetConnectionProfile | Select-Object Name,NetworkCategory\nGet-NetFirewallProfile | Format-Table Name,Enabled,DefaultInboundAction<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You should see a profile such as <code>Public<\/code> or <code>Private<\/code>, <code>Enabled<\/code> set to <code>True<\/code>, and normally <code>DefaultInboundAction<\/code> set to <code>Block<\/code>.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Name             Enabled DefaultInboundAction\n----             ------- --------------------\nPublic           True    Block\nPrivate          True    Block\nDomain           True    Block<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The displayed firewall profiles can all be enabled even though a network adapter is currently using only one category. Use the active category when you create the rule.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 3: Create the inbound rule with PowerShell<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">PowerShell makes the rule repeatable and gives it a clear name that you can audit or remove later.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The example below allows TCP port <code>8443<\/code> only on the server&#8217;s current network profile. Change the port, protocol, and rule name to match your application.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$Port = 8443\n$Protocol = \"TCP\"\n$RuleName = \"Allow TCP 8443\"\n$Profile = Get-NetConnectionProfile | Select-Object -First 1 -ExpandProperty NetworkCategory\nif ($Profile -eq \"DomainAuthenticated\") { $Profile = \"Domain\" }\nNew-NetFirewallRule -DisplayName $RuleName -Direction Inbound -Protocol $Protocol -LocalPort $Port -Action Allow -Profile $Profile<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A successful command returns a rule object with <code>Enabled : True<\/code>, <code>Direction : Inbound<\/code>, <code>Action : Allow<\/code>, and the selected profile. For UDP, set <code>$Protocol = \"UDP\"<\/code> and confirm the application has a UDP endpoint before testing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft&#8217;s <a href=\"https:\/\/learn.microsoft.com\/en-us\/powershell\/module\/netsecurity\/new-netfirewallrule\" target=\"_blank\" rel=\"noopener\">New-NetFirewallRule documentation<\/a> lists the available filters if you later need to restrict the rule to a program, address range, or service.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 4: Create the same rule in the firewall console<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The graphical wizard is useful when you want to review every profile and scope setting before saving the rule.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Open <strong>Server Manager \u2192 Tools \u2192 Windows Defender Firewall with Advanced Security<\/strong>. You can also press <code>Windows key + R<\/code>, enter <code>wf.msc<\/code>, and select <strong>OK<\/strong>.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>Select <strong>Inbound Rules<\/strong> in the left pane, then select <strong>New Rule&#8230;<\/strong> in the Actions pane.<\/li>\n\n\n<li>Select <strong>Port<\/strong>, choose <strong>TCP<\/strong> or <strong>UDP<\/strong>, and enter the local port. Use one port, a comma-separated list, or a range such as <code>8000-8010<\/code>.<\/li>\n\n\n<li>Select <strong>Allow the connection<\/strong>. Keep the rule limited to the required traffic; do not choose <strong>Allow the connection if it is secure<\/strong> unless you have configured IPsec.<\/li>\n\n\n<li>Select only the profile that matches the result from Step 2. Do not select every profile merely because it is convenient.<\/li>\n\n\n<li>Give the rule a specific name such as <code>Allow TCP 8443<\/code>, add a description with the application and owner, and select <strong>Finish<\/strong>.<\/li>\n\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The new entry should appear enabled in <strong>Inbound Rules<\/strong>. If a domain policy manages the server, the policy can override or replace local rules; make the change in the appropriate Group Policy when necessary. Microsoft explains the console workflow in its <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/security\/operating-system-security\/network-security\/windows-firewall\/configure\" target=\"_blank\" rel=\"noopener\">Windows Firewall rule configuration guide<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Verify the firewall rule and remote access<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">First confirm that Windows has the expected rule and port filter:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Get-NetFirewallRule -DisplayName \"Allow TCP 8443\" | Format-List DisplayName,Enabled,Direction,Action,Profile\nGet-NetFirewallRule -DisplayName \"Allow TCP 8443\" | Get-NetFirewallPortFilter | Format-List Protocol,LocalPort<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Expected output includes:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>DisplayName : Allow TCP 8443\nEnabled     : True\nDirection   : Inbound\nAction      : Allow\nProfile     : Public\nProtocol    : TCP\nLocalPort   : 8443<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">From a different computer, test the public address or DNS name. Replace <code>SERVER_IP<\/code> with the server address:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Test-NetConnection -ComputerName SERVER_IP -Port 8443<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The important result is <code>TcpTestSucceeded : True<\/code>. Run this test from outside the server; testing <code>localhost<\/code> only proves that the local machine can reach itself. For UDP, use the application&#8217;s client or protocol-specific test because <code>Test-NetConnection<\/code> checks TCP.<\/p>\n\n\n\n<aside class=\"vl-element vl-cta-banner\" aria-label=\"Need a Windows VPS?\">\n\t<div class=\"vl-cta-banner__content\">\n\t\t<p class=\"vl-cta-banner__eyebrow\">Windows Server hosting<\/p>\n\t\t<h3 class=\"vl-cta-banner__title\">Need a Windows VPS?<\/h3>\n\t\t<p class=\"vl-cta-banner__text\">Deploy your application on a Windows VPS with administrator access and control over firewall rules.<\/p>\n\t<\/div>\n\t<a class=\"vl-cta-banner__button\" href=\"\/buy-windows-rdp\" aria-label=\"View Windows VPS\">View Windows VPS<\/a>\n<\/aside>\n\n\n\n<h2 class=\"wp-block-heading\">Troubleshooting<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><code>TcpTestSucceeded : False<\/code> after adding the rule<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The service may not be listening, the rule may use the wrong protocol or profile, or an upstream provider firewall may be blocking the port. Repeat Step 1, inspect the rule&#8217;s port filter, and check any VPS control-panel or network security-group rules outside Windows.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The rule does not appear in the PowerShell query<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>Get-NetFirewallRule -DisplayName<\/code> requires an exact display name. List likely matches and check for a duplicate or different name:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Get-NetFirewallRule | Where-Object DisplayName -like \"*8443*\" | Format-Table DisplayName,Enabled,Direction,Action,Profile<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Use the exact returned name in later commands, or create one clearly named rule and remove an obsolete duplicate.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">It works on Private but not Public networks<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The rule is probably scoped to the wrong profile. Check <code>Get-NetConnectionProfile<\/code>, then edit the rule in <strong>Inbound Rules \u2192 Properties \u2192 Advanced \u2192 Profiles<\/strong>, or apply the active profile with:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Set-NetFirewallRule -DisplayName \"Allow TCP 8443\" -Profile Public<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Change <code>Public<\/code> only when it matches the server&#8217;s current network category. If you need the service available after profile changes, deliberately select the required profiles and understand the wider exposure.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">PowerShell reports \u201cAccess is denied\u201d<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Firewall changes require elevation. Close the current window, search for PowerShell, select <strong>Run as administrator<\/strong>, and run the command again. A standard RDP user cannot create local firewall rules without administrator rights or delegated permissions.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Hardening<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Limit <strong>Remote IP address<\/strong> in the rule properties when only a known office, monitoring host, or application tier needs access.<\/li>\n\n\n<li>Prefer a program-specific rule when the port belongs to one executable, rather than allowing every program to receive that traffic.<\/li>\n\n\n<li>Record the reason and owner in the rule description, then remove temporary rules after the migration or test is complete.<\/li>\n\n\n<li>Keep Windows Firewall enabled on every profile and manage provider-level firewall rules separately from the guest operating system.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">FAQ<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Does opening a firewall port start the application?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. The firewall rule only permits matching packets to reach Windows. The application must be installed, running, bound to the correct local address, and configured to use the same TCP or UDP port.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Should I choose TCP or UDP?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Choose the protocol specified by the application&#8217;s documentation. TCP and UDP are different transport protocols, so allowing TCP 8443 does not allow UDP 8443; create separate rules only when the service genuinely uses both.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Do I need an outbound rule too?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Usually not for a default Windows Server configuration, because outbound traffic is normally allowed unless a blocking rule or policy exists. Add an outbound allow rule only when your server has a restrictive outbound policy and the application requires it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How do I close the port later?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Disable the rule first if you may need it again, or remove it when it is no longer required:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Remove-NetFirewallRule -DisplayName \"Allow TCP 8443\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Confirm the display name before removal so you do not delete a different application&#8217;s rule.<\/p>\n\n\n\n<script type=\"application\/ld+json\">{\"@context\": \"https:\/\/schema.org\", \"@type\": \"FAQPage\", \"mainEntity\": [{\"@type\": \"Question\", \"name\": \"Does opening a firewall port start the application?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"No. The firewall rule only permits matching packets to reach Windows. The application must be installed, running, bound to the correct local address, and configured to use the same TCP or UDP port.\"}}, {\"@type\": \"Question\", \"name\": \"Should I choose TCP or UDP?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Choose the protocol specified by the application's documentation. TCP and UDP are different transport protocols, so allowing TCP 8443 does not allow UDP 8443; create separate rules only when the service genuinely uses both.\"}}, {\"@type\": \"Question\", \"name\": \"Do I need an outbound rule too?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Usually not for a default Windows Server configuration, because outbound traffic is normally allowed unless a blocking rule or policy exists. Add an outbound allow rule only when your server has a restrictive outbound policy and the application requires it.\"}}, {\"@type\": \"Question\", \"name\": \"How do I close the port later?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Disable the rule first if you may need it again, or remove it when it is no longer required: Confirm the display name before removal so you do not delete a different application's rule.\"}}]}<\/script>\n\n","protected":false},"excerpt":{"rendered":"Learn how to allow port in firewall on Windows Server 2016 with GUI and PowerShell, verify the listener, and fix common connection errors securely.","protected":false},"author":1,"featured_media":802,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"csco_singular_sidebar":"","csco_page_header_type":"","csco_page_load_nextpost":"","footnotes":""},"categories":[5,11],"tags":[39,38,37,36],"class_list":["post-801","post","type-post","status-publish","format-standard","has-post-thumbnail","category-guides","category-windows-server","tag-network-security","tag-powershell","tag-windows-firewall","tag-windows-server-2016","cs-entry"],"_links":{"self":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts\/801","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/comments?post=801"}],"version-history":[{"count":1,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts\/801\/revisions"}],"predecessor-version":[{"id":2898,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts\/801\/revisions\/2898"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/media\/802"}],"wp:attachment":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/media?parent=801"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/categories?post=801"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/tags?post=801"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}