How to Set Up and Configure Windows Defender Firewall for Maximum Security
Windows Defender Firewall is a built-in security tool that filters incoming and outgoing network traffic to block unauthorized access to your computer. Every Windows 10 and Windows 11 PC includes this software turned on by default to stop hackers and harmful apps from reaching your files over the internet.
Default settings often leave small security gaps open for advanced threats to slip through. Taking a few minutes to customize your firewall rules gives you total control over which apps can connect to the web. Open the Windows Security app in Windows 11 version 23H2 to block unauthorized network access across all 3 built-in network profiles, including Domain, Private, and Public networks.
Open the Windows Security app, click Firewall and network protection, select your active network profile, and turn on the firewall. Scroll down and check the box to block all incoming connections, including those in the list of allowed apps, to enforce maximum security on your device.
Understanding Windows Defender Firewall and Network Protection
Windows Defender Firewall is a built-in security tool that filters all incoming and outgoing network traffic to block unauthorized access to your computer. It monitors the connection between your device and the internet, stopping suspicious data packets before they can compromise your files or personal privacy.
Your firewall monitors network traffic by inspecting data packets (small chunks of data) traveling between your computer and other devices. Based on a strict set of safety rules, the firewall decides whether to let that data pass through or block it completely.
Your Windows computer divides your connections into different network types. Understanding these types helps you apply the right level of security:
- Private Networks: You choose this setting for trusted locations, such as your home network or a secure office network. Here, your computer can share files and printers with other trusted devices.
- Public Networks: You choose this setting for untrusted locations, such as public Wi-Fi at a coffee shop, airport, or hotel. This profile applies maximum security because anyone around you could be a potential threat.
The Windows Defender Firewall lowers your overall risk of computer infection by blocking unauthorized remote access. The Windows Defender Firewall stops malicious software from secretly talking to remote servers controlled by hackers.
How to Access and Check Your Firewall Status
Check your Windows Defender Firewall status by opening the Windows Security app and navigating to the network protection section. This screen shows you whether domain, private, and public networks are active and actively defending your device against external threats.
- Click the Start button on your taskbar and type Windows Security into the search box.
- Select the Windows Security app from the search results.
- Click on Firewall & network protection in the main window.
- Review your status for Domain network, Private network, and Public network. Each one should display as active and turned on.
If you see a warning symbol, your protection might be turned off. Re-enable protection by clicking the toggle switch for that network type.
Configuring Core Firewall Settings for Maximum Protection
Configure core Windows Defender Firewall settings by blocking all incoming connections that do not match an allowed rule to keep hackers out. Adjusting these protective settings inside the Windows Security app ensures maximum safety across your active domain, private, and public network profiles.
- Open the Windows Security app from your Start menu.
- Click on Firewall & network protection.
- Click on the specific network profile currently active on your computer, such as Public network.
- Locate the Microsoft Defender Firewall section.
- Ensure the toggle switch is turned to On.
- Scroll down and check the box labeled Block all incoming connections, including those in the list of allowed apps. *(Note: This step requires administrator privileges.)*
Use this setting if you want the highest level of lockdown while using untrusted public networks.
Next, make sure your notification settings are active so you know immediately if a program tries to bypass your security rules.
- Return to the main Firewall & network protection screen.
- Click on Allow an app through firewall to view what is currently permitted. *(Note: This step requires administrator privileges.)*
- Review the list of checked applications. Uncheck any programs you do not recognize or no longer use.
Creating Advanced Custom Rules for Enhanced Security
While the basic settings cover most situations, advanced users sometimes need to create custom rules to block specific network ports, IP addresses, or untrusted programs. The advanced security console lets you build these precise rules.
Creating an Inbound Port Rule
Block or allow traffic traveling through a specific communication channel on your PC by creating an inbound port rule. Setting up this rule using the Windows Defender Firewall with Advanced Security tool lets you target exact ports used by apps or potential threats.
- Click your Start button, type Windows Defender Firewall with Advanced Security, and open the tool. *(Note: This step requires administrator privileges.)*
- Click on Inbound Rules in the left-hand menu.
- Click on New Rule... in the right-hand actions panel.
- Select Port and click Next.
- Choose either TCP or UDP, then select Specific local ports and type your port number (for example, 80 or 443). Click Next.
- Select Block the connection and click Next.
- Check all network profiles (Domain, Private, Public) and click Next.
- Give your rule a clear name, such as Block Custom Port, and click Finish.
Creating an Inbound Program Rule
Stop a specific application from receiving unauthorized data from the internet by creating an inbound program rule in Windows Defender Firewall. Using the Windows Defender Firewall with Advanced Security tool lets you select any installed program and completely restrict its incoming network access.
- Open the Windows Defender Firewall with Advanced Security tool. *(Note: This step requires administrator privileges.)*
- Click on Inbound Rules in the left-hand menu.
- Click on New Rule... in the right-hand actions panel.
- Select Program and click Next.
- Browse to select the program file path (for example, C:\Program Files\ExampleApp\app.exe) and click Next.
- Select Block the connection and click Next.
- Select the network types where this rule applies and click Next.
- Type a descriptive name for the rule and click Finish.
Unique Security Angle: Monitoring Outbound Traffic
Monitor outbound traffic in Windows Defender Firewall to catch malicious software trying to send your personal data out to a remote server. Changing the default behavior to block outgoing connections by default adds an essential layer of security by watching every piece of data that leaves your computer.
By default, Windows allows all outbound traffic. Changing this behavior provides an extra layer of defense that stops rogue applications from communicating outside your machine.
- Open the Windows Defender Firewall with Advanced Security tool. *(Note: This step requires administrator privileges.)*
- Right-click on Windows Defender Firewall with Advanced Security at the top of the left menu and select Properties.
- Select the tab for your active profile (such as Public Profile).
- Locate the Outbound connections setting and change it from Allow to Block.
- Click Apply and then OK.
Only use this strict setting if you are prepared to manage individual app permissions.
Unique Security Angle: Auditing Firewall Logs for Suspicious Activity
Audit Windows Defender Firewall logs to review blocked connection attempts and spot repeated security attacks against your computer. Turning on this logging feature through the Windows Defender Firewall with Advanced Security tool helps you track network activity and investigate potential threats over time.
- Open the Windows Defender Firewall with Advanced Security tool. *(Note: This step requires administrator privileges.)*
- Click on Windows Defender Firewall Properties in the right-hand panel.
- Select the tab for the network profile you want to monitor (for example, Public Profile).
- Find the Logging section and click the Customize button next to it.
- Change Log dropped packets to Yes.
- Change Log successful connections to Yes if you want to track authorized traffic as well.
- Note the log file path (typically located at C:\Windows\system32\LogFiles\Firewall\pfirewall.log) and click OK.
Open this log file using a text editor like Notepad to review blocked connection attempts, IP addresses, and port numbers.
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard is a writer at Geek Rewind who turns complex IT tasks into clear, step-by-step guides. He draws on years of hands-on experience in system administration and enterprise IT operations, focusing on Windows, Linux and WordPress: the problems people actually run into, and the fixes that work. His server and WordPress guides come from systems he runs himself. Richard builds and maintains the platform behind Geek Rewind, from its Ubuntu servers and Nginx configuration to its custom WordPress plugins. Many new tutorials start with readers' questions, and he's always glad to answer them in the comments.
No comments yet — be the first to share your thoughts!