{"id":803,"date":"2026-10-10T13:00:00","date_gmt":"2026-10-10T13:00:00","guid":{"rendered":"https:\/\/vpslake.com\/blog\/?p=803"},"modified":"2026-10-10T13:00:00","modified_gmt":"2026-10-10T13:00:00","slug":"allow-port-firewall-windows-server-2019","status":"publish","type":"post","link":"https:\/\/vpslake.com\/blog\/2026\/10\/10\/allow-port-firewall-windows-server-2019\/","title":{"rendered":"Allow a Port in Windows Server 2019 Firewall"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">To allow port in firewall on Windows Server 2019, add a narrowly scoped inbound rule for the service&#8217;s TCP or UDP port. You can do it with PowerShell or the graphical console, then confirm the application is reachable from another computer in about ten minutes.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Prerequisites<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>A VPS running Windows Server 2019 with the application or service already installed.<\/li>\n\n\n<li>An active RDP session and a local administrator account, or an account permitted to open an elevated PowerShell window.<\/li>\n\n\n<li>The exact local port, transport protocol, and network profile required by the application. TCP and UDP are separate rules.<\/li>\n\n\n<li>The server&#8217;s public IP address or DNS name, plus a second computer from which you can test the connection.<\/li>\n\n\n<li>If you need a Windows environment for this guide, see <a href=\"https:\/\/vpslake.com\/buy-windows-rdp\">VPSLake Windows RDP hosting<\/a>.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Step 1: Confirm the service and port<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The firewall only filters traffic; it cannot make a stopped service listen, so check the application before changing the firewall.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Open <strong>Windows PowerShell<\/strong> as an administrator. Replace <code>8443<\/code> with the port your application uses:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$Port = 8443\nGet-NetTCPConnection -LocalPort $Port -State Listen -ErrorAction SilentlyContinue | Format-Table LocalAddress,LocalPort,OwningProcess,State\nGet-NetUDPEndpoint -LocalPort $Port -ErrorAction SilentlyContinue | Format-Table LocalAddress,LocalPort,OwningProcess<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For TCP, a row with <code>State<\/code> set to <code>Listen<\/code> means a process has bound the port. For UDP, the endpoint command should return a row; UDP does not have a TCP-style listening state.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example TCP output:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>LocalAddress LocalPort OwningProcess State\n------------ --------- ------------- -----\n0.0.0.0           8443          4120 Listen<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">No result usually means the application is stopped, bound to another port, or listening only on a different address. Fix that service-side issue before testing the firewall.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 2: Check the active firewall profile<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Windows applies a rule only when its profile matches the network category, so identify the active category before creating the exception.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Get-NetConnectionProfile | Format-Table InterfaceAlias,NetworkCategory,IPv4Connectivity,IPv6Connectivity\nGet-NetFirewallProfile | Format-Table Name,Enabled,DefaultInboundAction,DefaultOutboundAction<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">On an internet-facing VPS, the active category is commonly <code>Public<\/code>. The firewall should be enabled and the default inbound action should normally be <code>Block<\/code>:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Name    Enabled DefaultInboundAction DefaultOutboundAction\n----    ------- -------------------- ---------------------\nDomain     True                 Block                  Allow\nPrivate    True                 Block                  Allow\nPublic     True                 Block                  Allow<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Use the category shown for the server&#8217;s connected interface in the next step. Do not disable Windows Defender Firewall to make a connection test pass; that removes protection for every service.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 3: Add a specific inbound rule with PowerShell<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">PowerShell creates an auditable rule with a predictable name, which makes later verification and removal safer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The example permits TCP <code>8443<\/code> on the Public profile. Change <code>$Port<\/code>, <code>$RuleName<\/code>, <code>$Protocol<\/code>, and <code>$Profile<\/code> to match your service and the result from Step 2:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$Port = 8443\n$Protocol = \"TCP\"\n$RuleName = \"Allow TCP 8443 - Application\"\n$Profile = \"Public\"\nNew-NetFirewallRule -DisplayName $RuleName -Direction Inbound -Protocol $Protocol -LocalPort $Port -Action Allow -Profile $Profile -RemoteAddress Any | Select-Object DisplayName,Enabled,Direction,Action,Profile<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Expected output includes an enabled inbound allow rule:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>DisplayName                  Enabled Direction Action Profile\n-----------                  ------- --------- ------ -------\nAllow TCP 8443 - Application True    Inbound   Allow  Public<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For a UDP service, set <code>$Protocol = \"UDP\"<\/code>. If only a known office, monitoring host, or application server should connect, replace <code>Any<\/code> with its IP address or CIDR range, such as <code>203.0.113.25<\/code> or <code>203.0.113.0\/24<\/code>. A restricted source scope is safer for administration and internal services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/learn.microsoft.com\/en-us\/powershell\/module\/netsecurity\/new-netfirewallrule\" target=\"_blank\" rel=\"noopener\">Microsoft New-NetFirewallRule reference<\/a> documents additional filters for programs, services, interfaces, and remote addresses.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 4: Add the rule through the firewall console<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The GUI wizard is useful when you want to review the protocol, profiles, and connection scope before saving the rule.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Open <strong>Server Manager \u2192 Tools \u2192 Windows Defender Firewall with Advanced Security<\/strong>. You can also press <code>Windows key + R<\/code>, enter <code>wf.msc<\/code>, and select <strong>OK<\/strong>.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>Select <strong>Inbound Rules<\/strong> in the left pane, then select <strong>New Rule&#8230;<\/strong> in the Actions pane.<\/li>\n\n\n<li>Choose <strong>Port<\/strong>, select <strong>TCP<\/strong> or <strong>UDP<\/strong>, and enter the local port. A single port, comma-separated ports, or a range such as <code>8000-8010<\/code> is accepted.<\/li>\n\n\n<li>Select <strong>Allow the connection<\/strong>. Do not choose <strong>Allow the connection if it is secure<\/strong> unless you have separately configured IPsec.<\/li>\n\n\n<li>On <strong>Profile<\/strong>, select only the category identified in Step 2. Selecting every profile broadens the rule when the server changes networks.<\/li>\n\n\n<li>On <strong>Scope<\/strong>, restrict <strong>Remote IP address<\/strong> when the service does not need to accept connections from the entire internet.<\/li>\n\n\n<li>Enter a descriptive name such as <code>Allow TCP 8443 - Application<\/code>, add the service owner or purpose in the description, and select <strong>Finish<\/strong>.<\/li>\n\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The rule should appear enabled under <strong>Inbound Rules<\/strong>. Windows Server 2019 can also receive firewall policy from Active Directory; if a domain policy controls this server, make the change in the managed policy rather than relying only on a local rule. See Microsoft&#8217;s <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/security\/operating-system-security\/network-security\/windows-firewall\/configure\" target=\"_blank\" rel=\"noopener\">Windows Firewall configuration guide<\/a> for policy and console details.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Verify the firewall rule and remote connection<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">First inspect the saved rule and its port filter on the server. Use the same display name you created above:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$RuleName = \"Allow TCP 8443 - Application\"\nGet-NetFirewallRule -DisplayName $RuleName | Format-List DisplayName,Enabled,Direction,Action,Profile\nGet-NetFirewallRule -DisplayName $RuleName | Get-NetFirewallPortFilter | Format-List Protocol,LocalPort<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You should see <code>Enabled : True<\/code>, <code>Direction : Inbound<\/code>, <code>Action : Allow<\/code>, the intended profile, and <code>LocalPort : 8443<\/code>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">From a different computer\u2014not from the server itself\u2014replace <code>SERVER_IP<\/code> with the public address or DNS name:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Test-NetConnection -ComputerName SERVER_IP -Port 8443<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The key result is:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ComputerName     : SERVER_IP\nRemotePort       : 8443\nTcpTestSucceeded : True<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If the application speaks HTTP, you can also test it from a browser or with <code>curl.exe<\/code>. A successful TCP test proves the path and firewall rule work; the application still needs to return a valid protocol response.<\/p>\n\n\n\n<aside class=\"vl-element vl-cta-banner\" aria-label=\"Need a Windows VPS?\">\n\t<div class=\"vl-cta-banner__content\">\n\t\t<p class=\"vl-cta-banner__eyebrow\">Windows Server hosting<\/p>\n\t\t<h3 class=\"vl-cta-banner__title\">Need a Windows VPS?<\/h3>\n\t\t<p class=\"vl-cta-banner__text\">Run Windows applications with administrator access and control over firewall rules.<\/p>\n\t<\/div>\n\t<a class=\"vl-cta-banner__button\" href=\"\/buy-windows-rdp\" aria-label=\"View Windows VPS\">View Windows VPS<\/a>\n<\/aside>\n\n\n\n<h2 class=\"wp-block-heading\">Troubleshooting<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><code>TcpTestSucceeded : False<\/code><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The application may not be listening, the rule may use the wrong protocol or profile, or an upstream provider firewall may be blocking the port. Repeat Steps 1 and 2, inspect the exact rule, and check any VPS control-panel or network security-group firewall outside Windows.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The rule exists but the port is still unreachable<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Check for a more specific block rule, the server&#8217;s active profile, and the remote-address scope. These commands show matching rules and the current profile:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Get-NetConnectionProfile | Format-Table InterfaceAlias,NetworkCategory\nGet-NetFirewallRule -Direction Inbound -Enabled True | Where-Object DisplayName -like \"*8443*\" | Format-Table DisplayName,Profile,Action<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If the rule is scoped to <code>Public<\/code> but the connection uses <code>Private<\/code>, edit it under <strong>Inbound Rules \u2192 rule Properties \u2192 Advanced \u2192 Profiles<\/strong>, or recreate it for the profile the server actually uses.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">PowerShell reports <code>Access is denied<\/code><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Firewall changes require elevation. Close the current window, search for PowerShell, select <strong>Run as administrator<\/strong>, and run the command again. A standard RDP account cannot create local firewall rules without administrator rights or delegated permissions.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">It works locally but not from the internet<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Testing <code>localhost<\/code> or the server&#8217;s own IP can bypass part of the real network path. Confirm the service is bound to the correct interface, test from an outside network, and verify that the VPS provider&#8217;s perimeter firewall and any router or load balancer also allow the port.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Hardening<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Allow only the protocol and port the application needs; TCP and UDP require separate rules.<\/li>\n\n\n<li>Limit <strong>Remote IP address<\/strong> to trusted sources whenever a public service is not required.<\/li>\n\n\n<li>Prefer a program-specific rule for a single executable, and record the owner and purpose in the rule description.<\/li>\n\n\n<li>Disable a temporary rule during testing or remove it after the service is retired:<\/li>\n\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Remove-NetFirewallRule -DisplayName \"Allow TCP 8443 - Application\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Confirm the display name before removing anything, especially on a server with several similar rules.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">FAQ<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Does an inbound firewall rule start a Windows service?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. The rule only permits matching packets through Windows Defender Firewall. The service must be installed, running, bound to the intended local address, and configured to use the same port and protocol.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Should I allow a port on every firewall profile?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Usually no. Select the profile used by the server&#8217;s active network connection, and add other profiles only when you deliberately need the service available after a profile change. Selecting all profiles can expose the service on networks where it was not intended to run.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Do I need an outbound rule for the same port?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Not with the normal Windows Server policy, which permits outbound traffic by default. Create an outbound rule only if your server or domain policy blocks outbound connections and the application needs an exception.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How do I allow several ports safely?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Create separate rules when the ports belong to different services or need different source restrictions. A single rule can contain a comma-separated list or a range, but individual rules make auditing and later removal clearer.<\/p>\n\n\n\n<script type=\"application\/ld+json\">{\"@context\": \"https:\/\/schema.org\", \"@type\": \"FAQPage\", \"mainEntity\": [{\"@type\": \"Question\", \"name\": \"Does an inbound firewall rule start a Windows service?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"No. The rule only permits matching packets through Windows Defender Firewall. The service must be installed, running, bound to the intended local address, and configured to use the same port and protocol.\"}}, {\"@type\": \"Question\", \"name\": \"Should I allow a port on every firewall profile?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Usually no. Select the profile used by the server's active network connection, and add other profiles only when you deliberately need the service available after a profile change. Selecting all profiles can expose the service on networks where it was not intended to run.\"}}, {\"@type\": \"Question\", \"name\": \"Do I need an outbound rule for the same port?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Not with the normal Windows Server policy, which permits outbound traffic by default. Create an outbound rule only if your server or domain policy blocks outbound connections and the application needs an exception.\"}}, {\"@type\": \"Question\", \"name\": \"How do I allow several ports safely?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Create separate rules when the ports belong to different services or need different source restrictions. A single rule can contain a comma-separated list or a range, but individual rules make auditing and later removal clearer.\"}}]}<\/script>\n\n","protected":false},"excerpt":{"rendered":"Learn how to allow port in firewall on Windows Server 2019 with PowerShell or the GUI, confirm remote access, and fix common firewall errors safely.","protected":false},"author":1,"featured_media":804,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"csco_singular_sidebar":"","csco_page_header_type":"","csco_page_load_nextpost":"","footnotes":""},"categories":[5,11],"tags":[39,38,37,40],"class_list":["post-803","post","type-post","status-publish","format-standard","has-post-thumbnail","category-guides","category-windows-server","tag-network-security","tag-powershell","tag-windows-firewall","tag-windows-server-2019","cs-entry"],"_links":{"self":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts\/803","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/comments?post=803"}],"version-history":[{"count":1,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts\/803\/revisions"}],"predecessor-version":[{"id":3037,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts\/803\/revisions\/3037"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/media\/804"}],"wp:attachment":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/media?parent=803"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/categories?post=803"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/tags?post=803"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}