{"id":805,"date":"2026-10-10T18:00:00","date_gmt":"2026-10-10T18:00:00","guid":{"rendered":"https:\/\/vpslake.com\/blog\/?p=805"},"modified":"2026-10-10T18:00:00","modified_gmt":"2026-10-10T18:00:00","slug":"allow-port-firewall-windows-server-2025","status":"publish","type":"post","link":"https:\/\/vpslake.com\/blog\/2026\/10\/10\/allow-port-firewall-windows-server-2025\/","title":{"rendered":"Allow a Port in Windows Server 2025 Firewall"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">To allow port in firewall on Windows Server 2025, create a focused inbound rule for the service&#8217;s protocol and port, then test it from another device. The PowerShell method takes about ten minutes, and the same settings are available in the graphical firewall console.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Prerequisites<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>A VPS running Windows Server 2025 with the application or service installed and configured to use a known TCP or UDP port.<\/li>\n\n\n<li>An RDP session with a local administrator account, or another account that can open PowerShell as administrator.<\/li>\n\n\n<li>The port number, transport protocol, active Windows network profile, and the remote IP addresses that should be allowed.<\/li>\n\n\n<li>The server&#8217;s public IP address or DNS name and a separate computer for an external connection test.<\/li>\n\n\n<li>If you need a Windows environment for this procedure, see <a href=\"https:\/\/vpslake.com\/buy-windows-rdp\">VPSLake Windows RDP hosting<\/a>.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Step 1: Confirm that the application is listening<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The firewall can permit packets, but it cannot start a stopped service or correct an application bound to the wrong address.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Open <strong>Windows PowerShell<\/strong> with <strong>Run as administrator<\/strong>. Replace <code>8443<\/code> with the port used by your application:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$Port = 8443\nGet-NetTCPConnection -LocalPort $Port -State Listen -ErrorAction SilentlyContinue | Format-Table LocalAddress,LocalPort,OwningProcess,State\nGet-NetUDPEndpoint -LocalPort $Port -ErrorAction SilentlyContinue | Format-Table LocalAddress,LocalPort,OwningProcess<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A TCP service should return a row whose state is <code>Listen<\/code>. A UDP service should return an endpoint; UDP has no TCP-style listening state.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>LocalAddress LocalPort OwningProcess State\n------------ --------- ------------- -----\n0.0.0.0           8443          4120 Listen<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If both commands return nothing, start the service or change its configuration before editing the firewall. A listener on <code>127.0.0.1<\/code> is also not reachable from other machines until the application is configured to bind to the required server interface.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 2: Identify the active firewall profile<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Windows evaluates a rule against the profile used by the connected network adapter, so matching the profile prevents a rule that works only on the wrong network category.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Get-NetConnectionProfile | Format-Table InterfaceAlias,Name,NetworkCategory,IPv4Connectivity\nGet-NetFirewallProfile | Format-Table Name,Enabled,DefaultInboundAction,DefaultOutboundAction<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For an internet-facing VPS, the connected adapter is often <code>Public<\/code>, but use the value returned on your server. The firewall should be enabled and inbound traffic should normally default to <code>Block<\/code>:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Name    Enabled DefaultInboundAction DefaultOutboundAction\n----    ------- -------------------- ---------------------\nDomain     True                 Block                  Allow\nPrivate    True                 Block                  Allow\nPublic     True                 Block                  Allow<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If <code>NetworkCategory<\/code> is <code>DomainAuthenticated<\/code>, use <code>Domain<\/code> as the rule&#8217;s profile in the next step. Do not turn off Windows Defender Firewall as a workaround; that removes filtering for every service on the server.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 3: Create the inbound rule in PowerShell<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">PowerShell gives the exception a repeatable name and lets you review or remove it later without guessing which rule was changed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The following example allows TCP port <code>8443<\/code> on the <code>Public<\/code> profile. Change <code>$Port<\/code>, <code>$Protocol<\/code>, <code>$Profile<\/code>, and <code>$RuleName<\/code> to match your service and the result from Step 2:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$Port = 8443\n$Protocol = \"TCP\"\n$Profile = \"Public\"\n$RuleName = \"Allow TCP 8443 - Application\"\n\nNew-NetFirewallRule -DisplayName $RuleName -Direction Inbound -Protocol $Protocol -LocalPort $Port -Action Allow -Profile $Profile -RemoteAddress Any -Description \"Inbound access for the application on $Protocol port $Port\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The command should return an enabled inbound allow rule:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>DisplayName                  Enabled Direction Action Profile\n-----------                  ------- --------- ------ -------\nAllow TCP 8443 - Application True    Inbound   Allow  Public<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For a UDP service, set <code>$Protocol = \"UDP\"<\/code>; allowing TCP does not allow UDP on the same port. If the service is for an office, monitoring host, or private application tier, replace <code>Any<\/code> with the approved IP address or CIDR range, such as <code>203.0.113.25<\/code> or <code>203.0.113.0\/24<\/code>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft&#8217;s <a href=\"https:\/\/learn.microsoft.com\/en-us\/powershell\/module\/netsecurity\/new-netfirewallrule?view=windowsserver2025-ps\" target=\"_blank\" rel=\"noopener\">New-NetFirewallRule documentation<\/a> lists the available filters, including program, service, interface, and remote-address restrictions.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Step 4: Add the same exception in the graphical console<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The firewall console is useful when you want to review the rule&#8217;s profile and connection scope before saving it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Open <strong>Server Manager \u2192 Tools \u2192 Windows Defender Firewall with Advanced Security<\/strong>. Alternatively, press <code>Windows key + R<\/code>, enter <code>wf.msc<\/code>, and select <strong>OK<\/strong>.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>Select <strong>Inbound Rules<\/strong>, then choose <strong>New Rule&#8230;<\/strong> in the Actions pane.<\/li>\n\n\n<li>Select <strong>Port<\/strong>, choose <strong>TCP<\/strong> or <strong>UDP<\/strong>, and enter the local port. Use a single port unless the same application genuinely needs a list or range.<\/li>\n\n\n<li>Select <strong>Allow the connection<\/strong>. Leave <strong>Allow the connection if it is secure<\/strong> for environments where IPsec has been configured deliberately.<\/li>\n\n\n<li>On <strong>Profile<\/strong>, select the active profile from Step 2. Select additional profiles only if the service must remain reachable after the network category changes.<\/li>\n\n\n<li>On <strong>Scope<\/strong>, limit <strong>Remote IP address<\/strong> when the service is not intended for the whole internet.<\/li>\n\n\n<li>Enter a name such as <code>Allow TCP 8443 - Application<\/code>, add the purpose and owner in <strong>Description<\/strong>, and select <strong>Finish<\/strong>.<\/li>\n\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The rule should now appear as enabled under <strong>Inbound Rules<\/strong>. If Group Policy manages the server&#8217;s firewall, a domain administrator may need to make the change in the controlling policy instead of relying on a local rule. Microsoft&#8217;s <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/security\/operating-system-security\/network-security\/windows-firewall\/configure\" target=\"_blank\" rel=\"noopener\">Windows Firewall configuration guide<\/a> covers the policy and console model.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Verify the firewall rule and remote access<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">First confirm that Windows saved the intended rule and port filter:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$RuleName = \"Allow TCP 8443 - Application\"\nGet-NetFirewallRule -DisplayName $RuleName | Format-List DisplayName,Enabled,Direction,Action,Profile\nGet-NetFirewallRule -DisplayName $RuleName | Get-NetFirewallPortFilter | Format-List Protocol,LocalPort<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Look for <code>Enabled : True<\/code>, <code>Direction : Inbound<\/code>, <code>Action : Allow<\/code>, the expected profile, <code>Protocol : TCP<\/code>, and <code>LocalPort : 8443<\/code>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">From a different computer, test the public address. Replace <code>SERVER_IP<\/code> with the server&#8217;s IP address or DNS name:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Test-NetConnection -ComputerName SERVER_IP -Port 8443<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The important result is:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ComputerName     : SERVER_IP\nRemotePort       : 8443\nTcpTestSucceeded : True<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This test proves that a TCP connection can cross the network path and reach the port. For UDP, use the application&#8217;s client or a protocol-specific probe because <code>Test-NetConnection<\/code> checks TCP, not UDP. Testing <code>localhost<\/code> on the server does not prove that an outside client can connect.<\/p>\n\n\n\n<aside class=\"vl-element vl-cta-banner\" aria-label=\"Need a Windows VPS?\">\n\t<div class=\"vl-cta-banner__content\">\n\t\t<p class=\"vl-cta-banner__eyebrow\">Windows Server hosting<\/p>\n\t\t<h3 class=\"vl-cta-banner__title\">Need a Windows VPS?<\/h3>\n\t\t<p class=\"vl-cta-banner__text\">Run Windows applications with administrator access and control over firewall rules.<\/p>\n\t<\/div>\n\t<a class=\"vl-cta-banner__button\" href=\"\/buy-windows-rdp\" aria-label=\"View Windows VPS\">View Windows VPS<\/a>\n<\/aside>\n\n\n\n<h2 class=\"wp-block-heading\">Troubleshooting<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><code>TcpTestSucceeded : False<\/code><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The service may not be listening, the rule may use the wrong protocol or profile, or a provider-level firewall may block the port before traffic reaches Windows. Recheck Step 1, inspect the rule&#8217;s port filter, and review any VPS control-panel or upstream security-group rules.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The rule exists, but Windows still blocks the connection<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Look for a profile mismatch, a remote-address restriction, or a more specific block rule. These commands show the active category and enabled inbound rules that mention the example port:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Get-NetConnectionProfile | Format-Table InterfaceAlias,NetworkCategory\nGet-NetFirewallRule -Direction Inbound -Enabled True | Where-Object DisplayName -like \"*8443*\" | Format-Table DisplayName,Profile,Action<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If the rule is <code>Public<\/code> but the adapter is <code>Private<\/code>, edit <strong>Inbound Rules \u2192 rule Properties \u2192 Advanced \u2192 Profiles<\/strong>, or recreate the rule with the active profile.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">PowerShell returns <code>Access is denied<\/code><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The firewall cmdlets require elevation. Close the current window, search for PowerShell, select <strong>Run as administrator<\/strong>, and run the command again. A standard RDP account cannot create local firewall rules without administrator rights or delegated permissions.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The port works on the server but not from the internet<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A local test can bypass the real route and external filtering. Confirm that the application listens on the server&#8217;s reachable address, test from another network, and check the provider&#8217;s perimeter firewall, NAT, load balancer, or security group.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Hardening<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Allow only the protocol and port the application requires; TCP and UDP need separate rules.<\/li>\n\n\n<li>Restrict <strong>Remote IP address<\/strong> to trusted sources for administration, databases, dashboards, and internal APIs.<\/li>\n\n\n<li>Keep a descriptive rule name and description so another administrator can identify its owner and purpose.<\/li>\n\n\n<li>Disable a temporary exception during testing or remove it when the service is retired:<\/li>\n\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>Remove-NetFirewallRule -DisplayName \"Allow TCP 8443 - Application\"<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Confirm the display name before removing a rule on a production server.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">FAQ<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Does opening a port start the Windows service?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. A firewall rule only controls whether matching packets may pass. The service must be installed, running, bound to the correct local address, and configured for the same protocol and port.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Should I select Domain, Private, and Public profiles?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Usually not. Select the profile used by the server&#8217;s connected adapter and add others only when the application must remain reachable after a deliberate profile change. Selecting all three can expose the service on a network where it was not intended to run.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Do I need an outbound rule for the same port?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Normally no: Windows Server commonly allows outbound traffic by default. Create an outbound rule only when a restrictive local policy or Group Policy blocks outbound connections needed by the application.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How can I allow several ports?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You can enter a comma-separated list or range when the ports share the same protocol, profile, and security scope. Separate rules are easier to audit when different services need different source restrictions.<\/p>\n\n\n\n<script type=\"application\/ld+json\">{\"@context\": \"https:\/\/schema.org\", \"@type\": \"FAQPage\", \"mainEntity\": [{\"@type\": \"Question\", \"name\": \"Does opening a port start the Windows service?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"No. A firewall rule only controls whether matching packets may pass. The service must be installed, running, bound to the correct local address, and configured for the same protocol and port.\"}}, {\"@type\": \"Question\", \"name\": \"Should I select Domain, Private, and Public profiles?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Usually not. Select the profile used by the server's connected adapter and add others only when the application must remain reachable after a deliberate profile change. Selecting all three can expose the service on a network where it was not intended to run.\"}}, {\"@type\": \"Question\", \"name\": \"Do I need an outbound rule for the same port?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Normally no: Windows Server commonly allows outbound traffic by default. Create an outbound rule only when a restrictive local policy or Group Policy blocks outbound connections needed by the application.\"}}, {\"@type\": \"Question\", \"name\": \"How can I allow several ports?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"You can enter a comma-separated list or range when the ports share the same protocol, profile, and security scope. Separate rules are easier to audit when different services need different source restrictions.\"}}]}<\/script>\n\n","protected":false},"excerpt":{"rendered":"Learn to allow port in firewall on Windows Server 2025 with PowerShell or the GUI, test the listener remotely, and fix blocked connections.","protected":false},"author":1,"featured_media":806,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"csco_singular_sidebar":"","csco_page_header_type":"","csco_page_load_nextpost":"","footnotes":""},"categories":[5,11],"tags":[39,38,37,41],"class_list":["post-805","post","type-post","status-publish","format-standard","has-post-thumbnail","category-guides","category-windows-server","tag-network-security","tag-powershell","tag-windows-firewall","tag-windows-server-2025","cs-entry"],"_links":{"self":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts\/805","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/comments?post=805"}],"version-history":[{"count":1,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts\/805\/revisions"}],"predecessor-version":[{"id":3038,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/posts\/805\/revisions\/3038"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/media\/806"}],"wp:attachment":[{"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/media?parent=805"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/categories?post=805"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vpslake.com\/blog\/wp-json\/wp\/v2\/tags?post=805"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}