| Policy | Setting | Comment |
| Windows Defender Firewall: Allow ICMP exceptions | Enabled | |
| Allow outbound destination unreachable | Enabled |
| Allow outbound source quench | Enabled |
| Allow redirect | Enabled |
| Allow inbound echo request | Enabled |
| Allow inbound router request | Enabled |
| Allow outbound time exceeded | Enabled |
| Allow outbound parameter problem | Enabled |
| Allow inbound timestamp request | Enabled |
| Allow inbound mask request | Enabled |
| Allow outbound packet too big | Enabled |
|
| Policy | Setting | Comment |
| Windows Defender Firewall: Allow inbound file and printer sharing exception | Enabled | |
| Allow unsolicited incoming messages from these IP addresses: | 10.238.81.0/24,10.240.86.0/24,10.238.85.0/24,10.239.131.0/24 |
| Syntax: | | Type "*" to allow messages from any network, or | | else type a comma-separated list that contains | | any number or combination of these: | | IP addresses, such as 10.0.0.1 | | Subnet descriptions, such as 10.2.3.0/24 | | The string "localsubnet" | | Example: to allow messages from 10.0.0.1, | | 10.0.0.2, and from any system on the | | local subnet or on the 10.3.4.x subnet, | | type the following in the "Allow unsolicited" | | incoming messages from these IP addresses": | | 10.0.0.1,10.0.0.2,localsubnet,10.3.4.0/24 | |
| Policy | Setting | Comment |
| Windows Defender Firewall: Allow inbound remote administration exception | Enabled | |
| Allow unsolicited incoming messages from these IP addresses: | 10.238.81.0/24,10.240.86.0/24,10.238.85.0/24,10.239.131.0/24 |
| Syntax: | | Type "*" to allow messages from any network, or | | else type a comma-separated list that contains | | any number or combination of these: | | IP addresses, such as 10.0.0.1 | | Subnet descriptions, such as 10.2.3.0/24 | | The string "localsubnet" | | Example: to allow messages from 10.0.0.1, | | 10.0.0.2, and from any system on the | | local subnet or on the 10.3.4.x subnet, | | type the following in the "Allow unsolicited" | | incoming messages from these IP addresses": | | 10.0.0.1,10.0.0.2,localsubnet,10.3.4.0/24 | |
| Policy | Setting | Comment |
| Windows Defender Firewall: Allow inbound UPnP framework exceptions | Enabled | |
| Allow unsolicited incoming messages from these IP addresses: | 10.238.81.0/24,10.240.86.0/24,10.238.85.0/24,10.239.131.0/24 |
| Syntax: | | Type "*" to allow messages from any network, or | | else type a comma-separated list that contains | | any number or combination of these: | | IP addresses, such as 10.0.0.1 | | Subnet descriptions, such as 10.2.3.0/24 | | The string "localsubnet" | | Example: to allow messages from 10.0.0.1, | | 10.0.0.2, and from any system on the | | local subnet or on the 10.3.4.x subnet, | | type the following in the "Allow unsolicited" | | incoming messages from these IP addresses": | | 10.0.0.1,10.0.0.2,localsubnet,10.3.4.0/24 | |
| Policy | Setting | Comment |
| Windows Defender Firewall: Allow local port exceptions | Enabled | |
| Windows Defender Firewall: Allow local program exceptions | Enabled | |
| Windows Defender Firewall: Define inbound port exceptions | Enabled | |
| Define port exceptions: |
| *:*:10.238.81.0/24:enabled:ITAccess |
| *:*:172.16.1.0/24:enabled:ServerAccess |
| *:*:10.238.85.0/24:enabled:ServersAccess |
| *:*:10.240.86.0/24:enabled:Servers3Access |
| *:*:10.239.131.0/24:enabled:ITAccess2 |
| | Specify the port to open or block. | | Syntax: | | <Port>:<Transport>:<Scope>:<Status>:<Name> | | <Port> is a decimal port number | | <Transport> is either "TCP" or "UDP" | | <Scope> is either "*" (for all networks) or | | a comma-separated list that contains | | any number or combination of these: | | IP addresses, such as 10.0.0.1 | | Subnet descriptions, such as 10.2.3.0/24 | | The string "localsubnet" | | <Status> is either "enabled" or "disabled" | | <Name> is a text string | | Example: | | The following definition string adds TCP port 80 | | to the port exceptions list and allows it to | | receive messages from 10.0.0.1, 10.0.0.2, or any | | system on the 10.3.4.x subnet: | | 80:TCP:10.0.0.1,10.0.0.2,10.3.4.0/24:enabled:Web service | |
| Policy | Setting | Comment |
| Windows Defender Firewall: Protect all network connections | Disabled | |