Please, don’t turn your firewall off…

๐——๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜ โ†’ ๐—›๐—ฎ๐—ฟ๐—ฑ๐—ฒ๐—ป๐—ฒ๐—ฑ

Real configs. Real fixes. Windows & AD security.

๐—ฃ๐—น๐—ฒ๐—ฎ๐˜€๐—ฒ, ๐—ฑ๐—ผ๐—ปโ€™๐˜ ๐˜๐˜‚๐—ฟ๐—ป ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ณ๐—ถ๐—ฟ๐—ฒ๐˜„๐—ฎ๐—น๐—น ๐—ผ๐—ณ๐—ณโ€ฆ

It might sound surprising, but I still see this way too often:

โš ๏ธ Windows Firewall completely disabled for no real reason.

Sometimes it almost feels like the deployment process is:

โžก๏ธ Install Windows Server โžก๏ธ sign in โžก๏ธ disable Windows Firewall

I always ask ๐˜„๐—ต๐˜†, and the answer is usually some ๐—ผ๐—น๐—ฑ ๐—ฏ๐—ฎ๐—ฑ ๐—ฒ๐˜…๐—ฝ๐—ฒ๐—ฟ๐—ถ๐—ฒ๐—ป๐—ฐ๐—ฒ. Something did not work years ago, the firewall was blamed, and since then it has simply been disabled everywhere.

โŒ That is a ๐—ต๐˜‚๐—ด๐—ฒ ๐—บ๐—ถ๐˜€๐˜๐—ฎ๐—ธ๐—ฒ.

Even with good network segmentation, Windows Firewall can still protect devices inside the same network segment after an attacker gets in. Without host-level filtering, ๐—น๐—ฎ๐˜๐—ฒ๐—ฟ๐—ฎ๐—น ๐—บ๐—ผ๐˜ƒ๐—ฒ๐—บ๐—ฒ๐—ป๐˜ between systems becomes much easier.

โœ… At the very least, ๐—ฒ๐—ป๐—ณ๐—ผ๐—ฟ๐—ฐ๐—ฒ the enabled state through Group Policy.

๐Ÿ”น From there, ๐—ฑ๐—ฒ๐—ณ๐—ถ๐—ป๐—ฒ ๐—ฟ๐˜‚๐—น๐—ฒ๐˜€ for each group of devices based on what they actually need.

๐Ÿ”น Once you have central rule management in place, you can also decide whether ๐—น๐—ผ๐—ฐ๐—ฎ๐—น๐—น๐˜† ๐—ฐ๐—ฟ๐—ฒ๐—ฎ๐˜๐—ฒ๐—ฑ ๐—ณ๐—ถ๐—ฟ๐—ฒ๐˜„๐—ฎ๐—น๐—น ๐—ฟ๐˜‚๐—น๐—ฒ๐˜€ should be allowed or ignored.

And Windows Firewall can do much more than simply allow or block ports. Once you understand it properly, it becomes a very powerful security control.

I remember an excellent article from Michael Waterman about using Windows Firewall to create something like ๐—ฐ๐—ผ๐—ป๐—ฑ๐—ถ๐˜๐—ถ๐—ผ๐—ป๐—ฎ๐—น ๐—ฎ๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€.

โš ๏ธ And even if you use another firewall product, or Windows Firewall is managed through another platform, please review the resulting rules.

โžก๏ธ More than once, I have found an ๐—ฎ๐—น๐—น๐—ผ๐˜„ ๐—ฎ๐—ป๐˜† / ๐—ฎ๐—ป๐˜† rule at the end of the list…

๐—œ๐—ณ ๐˜†๐—ผ๐˜‚ ๐˜๐—ฎ๐—ธ๐—ฒ ๐—ผ๐—ป๐—น๐˜† ๐—ผ๐—ป๐—ฒ ๐˜๐—ต๐—ถ๐—ป๐—ด ๐—ณ๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ถ๐˜€ ๐—ฝ๐—ผ๐˜€๐˜:

โœ… Please, do not turn it off.

If you are interested in securing Windows infrastructure properly, I created a condensed course called ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—œ๐—ป๐—ณ๐—ฟ๐—ฎ๐˜€๐˜๐—ฟ๐˜‚๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜†. It is available online, and free previews are available so you can check the content first.

Do you centrally manage Windows Firewall in your environment, or is it still handled differently on every server?