Skip to main content

System Status: 

Setting Up a Firewall: Windows 7 - Advanced

Learn how to use advanced settings for the Windows 7 firewall to create exceptions for specific services.

Before starting, disable all firewalls on your machine, including the Windows 7 firewall. Do not use Remote Desktop Connection (RDC) or a similar program to install firewall software. Directly connect to your Windows machine, install the firewall, configure it to allow connections to and from RDC, and then reconnect RDC. Otherwise, the firewall blocks the remote connection, and you cannot access your machine.

1. Choose security settings.

The firewall automatically blocks access to your computer from outside applications and asks you what to do. Either click Allow Access, and follow the steps below, or block access and click Cancel.

step 1

2. Manually allow programs through firewall.

  1. To manually allow a program through the firewall, open the Control Panel from the Start menu
  2. Select System and Security, then select Windows Firewall
  3. Click Allow a program or feature through Windows Firewall in the left column of the window
    1. step 2

  4. Click the Change settings button in the Allowed Programs window
  5. Select the program or feature and whether you want to open it up to home/work (private), public, or both for all networks
  6. Click OK to save your changes

step 3

3. Create a rule to enable services

  1. Create rule type:
    1. Click Advanced settings
    2. Select Inbound Rules in the left column
    3. Select New Rule. on the right side of the window
    4. Select Port in the New Inbound Rule Wizard and then click Next
    5. step 4

  2. Specify rule protocols and ports:
    1. Select TCP or UDP (which protocol this rule will apply to)
    2. Select Specific local ports, type a port number (80), port numbers (80,81), or a range of port numbers (5000-5010), then click Next
    3. step 5

  3. Specify rule actions:
    1. Select Allow the connection and click Next
    2. step 6

  4. Specify rule profiles:
    1. Select when this rule applies based on your profiles
      • To learn more about profiles, click Learn more about profiles located in the lower half of the window
    2. Select all of the profiles (Domain, Private, Public) only if you want the requests from this port to allow access through the firewall no matter which connection/profile type you are using
    3. Click Next
    4. Step 7

  5. Specify rule name
    1. Give this rule a name (see image below as an example)
    2. Click Finish to add the new rule

step 8

4. Enable logging to view denied incoming connections

  1. Click Advanced Settings on the left-hand side of Windows Firewall, then click Properties
  2. Click the Public Profile tab
  3. Click the Customize tab next to Logging
    1. step 9

  4. Customize logging settings:
    1. Click the pull-down menu for Log dropped packets, change to Yes
    2. Click OK, click Apply, and click OK

step 10

5. Ensure firewall is enabled

  1. From the Control panel, click System and Security
  2. Click Check firewall status under Windows Firewall

step 11

For more information, contact IT Services Security at security@ucsd.edu.