Mondoo Docs

Windows Firewall profile entry

Windows Firewall profile configuration

Operating System

Windows Firewall profile entry

https://docs.microsoft.com/en-us/previous-versions/windows/desktop/wfascimprov/msft-netfirewallprofile

Use MQL in cnspec shell or policy:

windows.firewall.profile
Min version: 5.15.0

Relationships

Mini Map
Operating System
2 resources · 2 relationshipsClick to select, expand fields to see properties.

Fields (18)

FieldTypeDescription
allowInboundRulesrequired
intWhether administrators can create firewall rules that allow unsolicited inbound traffic (if 0, such rules are ignored)
allowLocalFirewallRulesrequired
intWhether local firewall rules should merge into the effective policy along with group policy settings
allowLocalIPsecRulesrequired
intWhether local IPsec rules should merge into the effective policy along with rules from group policy
allowUnicastResponseToMulticastrequired
intWhether to allow unicast responses to multicast traffic
allowUserAppsrequired
intWhether to respect user allowed applications created in the legacy firewall
allowUserPortsrequired
intWhether to respect globally opened ports created in the legacy firewall
defaultInboundActionrequired
intDefault action for inbound traffic
defaultOutboundActionrequired
intDefault action for outbound traffic
enabledrequired
intWhether the firewall is enabled on this profile
enableStealthModeForIPsecrequired
intWhether to use stealth mode for IPsec-protected traffic
instanceIDrequired
string-
logAllowedrequired
intWhether to log allowed packets
logBlockedrequired
intWhether to log blocked traffic
logFileNamerequired
stringFilename in which to store the firewall log
logIgnoredrequired
intWhether to log an event when rules are ignored
logMaxSizeKilobytesrequired
intMaximum size the log file can reach before being rotated
namerequired
stringName of the profile
notifyOnListenrequired
intWhether to notify users when an application listens on a port that is closed