Windows Firewall scope is not working

somedude133466 1 Reputation point
2021-04-27T13:52:11.817+00:00

I have to block all connections except some IP for RDP so I create a windows firewall rule.
91755-image.png

I create a rule that allows connections to the port 3389 only for 192.168.2.50

91756-image.png

All profiles have the settings to reject all connections not specified by a rule .
91781-image.png

I think it is all correct i apply. When I try to connect (RDP is activated in the computer where rule is being applied) connection is refused.

91743-image.png

If I change the rule and allow all IP to connect via RDP.
91791-image.png

I have no problem connecting, but all IP can connect via RDP.
91772-image.png

I don't now why this is happening

(This problem is not only happening with RDP, also happens with ICMPv4,VNC...)

Windows Network
Windows Network
Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.Network: A group of devices that communicate either wirelessly or via a physical connection.
686 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Sunny Qi 10,916 Reputation points Microsoft Vendor
    2021-04-28T08:01:50.817+00:00

    Hi,

    Thanks for posting in Q&A platform.

    May I know if your goal is block all IP to connection port 3389 except for the specific IP 192.168.2.50? If yes, create a new rule in Inbound Rules might not achieve your goal.

    I have test in my lab environment and attaching the result for your reference:

    I created a new rule in Inbound rules as the information you provided, I found the specific IP can RDP to the target machine, but the other IP can also RDP to the target machine.

    91958-image-42.png

    92042-image-43.png

    92015-image-44.png

    92032-image-41.png

    92033-image-45.png

    If you just need the specific IP can RDP to the target machine via port 3389, I would suggest you could specify the specific remote IP in the following rules of Inbound rules in Windows Firewall:

    Remote Desktop - user Mode (TCP-In)

    Remote Desktop -User Mode (UDP-In)

    91948-image.png

    Best Regards,
    Sunny

    ----------

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments