| Policy | Setting | Comment |
| Windows Defender Firewall: Allow ICMP exceptions | Enabled | |
| Allow outbound destination unreachable | Disabled |
| Allow outbound source quench | Disabled |
| Allow redirect | Disabled |
| Allow inbound echo request | Enabled |
| Allow inbound router request | Enabled |
| Allow outbound time exceeded | Disabled |
| Allow outbound parameter problem | Disabled |
| Allow inbound timestamp request | Disabled |
| Allow inbound mask request | Disabled |
| Allow outbound packet too big | Disabled |
|
| Policy | Setting | Comment |
| Windows Defender Firewall: Allow inbound remote administration exception | Enabled | |
| Allow unsolicited incoming messages from these IP addresses: | * |
| Syntax: | | Type "*" to allow messages from any network, or | | else type a comma-separated list that contains | | any number or combination of these: | | IP addresses, such as 10.0.0.1 | | Subnet descriptions, such as 10.2.3.0/24 | | The string "localsubnet" | | Example: to allow messages from 10.0.0.1, | | 10.0.0.2, and from any system on the | | local subnet or on the 10.3.4.x subnet, | | type the following in the "Allow unsolicited" | | incoming messages from these IP addresses": | | 10.0.0.1,10.0.0.2,localsubnet,10.3.4.0/24 | |
| Policy | Setting | Comment |
| Windows Defender Firewall: Allow inbound Remote Desktop exceptions | Enabled | |
| Allow unsolicited incoming messages from these IP addresses: | * |
| Syntax: | | Type "*" to allow messages from any network, or | | else type a comma-separated list that contains | | any number or combination of these: | | IP addresses, such as 10.0.0.1 | | Subnet descriptions, such as 10.2.3.0/24 | | The string "localsubnet" | | Example: to allow messages from 10.0.0.1, | | 10.0.0.2, and from any system on the | | local subnet or on the 10.3.4.x subnet, | | type the following in the "Allow unsolicited" | | incoming messages from these IP addresses": | | 10.0.0.1,10.0.0.2,localsubnet,10.3.4.0/24 | |
| Policy | Setting | Comment |
| Windows Defender Firewall: Protect all network connections | Enabled | |