| Policy | Setting | Comment |
| Windows Defender Firewall: Allow ICMP exceptions | Enabled | |
| Allow outbound destination unreachable | Enabled |
| Allow outbound source quench | Enabled |
| Allow redirect | Enabled |
| Allow inbound echo request | Enabled |
| Allow inbound router request | Enabled |
| Allow outbound time exceeded | Enabled |
| Allow outbound parameter problem | Enabled |
| Allow inbound timestamp request | Enabled |
| Allow inbound mask request | Enabled |
| Allow outbound packet too big | Enabled |
|
| Policy | Setting | Comment |
| Windows Defender Firewall: Allow inbound file and printer sharing exception | Enabled | |
| Allow unsolicited incoming messages from these IP addresses: | |
| Syntax: | | Type "*" to allow messages from any network, or | | else type a comma-separated list that contains | | any number or combination of these: | | IP addresses, such as 10.0.0.1 | | Subnet descriptions, such as 10.2.3.0/24 | | The string "localsubnet" | | Example: to allow messages from 10.0.0.1, | | 10.0.0.2, and from any system on the | | local subnet or on the 10.3.4.x subnet, | | type the following in the "Allow unsolicited" | | incoming messages from these IP addresses": | | 10.0.0.1,10.0.0.2,localsubnet,10.3.4.0/24 | |
| Policy | Setting | Comment |
| Windows Defender Firewall: Allow inbound remote administration exception | Enabled | |
| Allow unsolicited incoming messages from these IP addresses: | |
| Syntax: | | Type "*" to allow messages from any network, or | | else type a comma-separated list that contains | | any number or combination of these: | | IP addresses, such as 10.0.0.1 | | Subnet descriptions, such as 10.2.3.0/24 | | The string "localsubnet" | | Example: to allow messages from 10.0.0.1, | | 10.0.0.2, and from any system on the | | local subnet or on the 10.3.4.x subnet, | | type the following in the "Allow unsolicited" | | incoming messages from these IP addresses": | | 10.0.0.1,10.0.0.2,localsubnet,10.3.4.0/24 | |
| Policy | Setting | Comment |
| Windows Defender Firewall: Allow inbound Remote Desktop exceptions | Enabled | |
| Allow unsolicited incoming messages from these IP addresses: | |
| Syntax: | | Type "*" to allow messages from any network, or | | else type a comma-separated list that contains | | any number or combination of these: | | IP addresses, such as 10.0.0.1 | | Subnet descriptions, such as 10.2.3.0/24 | | The string "localsubnet" | | Example: to allow messages from 10.0.0.1, | | 10.0.0.2, and from any system on the | | local subnet or on the 10.3.4.x subnet, | | type the following in the "Allow unsolicited" | | incoming messages from these IP addresses": | | 10.0.0.1,10.0.0.2,localsubnet,10.3.4.0/24 | |
| Policy | Setting | Comment |
| Windows Defender Firewall: Allow local program exceptions | Enabled | |
| Windows Defender Firewall: Prohibit notifications | Disabled | |
| Windows Defender Firewall: Prohibit unicast response to multicast or broadcast requests | Disabled | |
| Windows Defender Firewall: Protect all network connections | Enabled | |