Share via

Firewall rule doesn't work

Anonymous
2019-01-15T18:06:06+00:00

Hi,

my default setting for the firewall is to block all traffic. Exceptions are added if necessary. This strategy will not be changed for there is no clarity regarding all the traffic going on. For instance, two exceptions enable DNS and DHCP. This works well. Another one is svchost, service="Cryptographic services" (CryptSvc). The latter does not work. This means, the firewall still blocks these packets. I have verified my rule multiple times, even removed it and added it again.

As the normal firewall log file isn't speaking enough, I have enabled logging of dropped packets in the event log via group policies. I wrote a little program for live observation of these log entries. Thereby, I am able to lookup the services from the logged process ID.

The firewall rule exactly matches this case. Consequently, the packet should not be blocked. The rule is: Allow, Outgoing, program=svchost, service=CryptSvc, all profiles, all local ports, all IPs, protocol TCP, remote ports 80 and 443.

So my question is: Why does the firewall block packets even if a rule allows them? (There is no other rule denying it)

Win 10 x64 Pro

Thanks

Windows for home | Windows 10 | Internet and connectivity

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

Answer accepted by question author

Anonymous
2019-01-16T08:21:51+00:00

Hi,

Thank you for posting your concern on Microsoft Answer Community.

I understand the inconvenience that can be caused when certain features do not work the way it is supposed to. However, we would like you to check with our Technet forum team to make custom rule on firewall settings, I would suggest you to post your query in TechNet forums, where we have the engineers with the expertise to provide solutions for issues related to custom firewall rule settings.

Aditya Roy

Microsoft Community – Moderator

Was this answer helpful?

0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Anonymous
    2019-01-16T11:54:02+00:00

    Thanks you Aditya Roy, I will post it in a TechNet forum.

    EDIT: Done here.

    Was this answer helpful?

    0 comments No comments