When a game, printer or local service cannot connect, disabling the firewall appears to solve the immediate symptom but exposes unrelated services. Microsoft considers an app allow rule less risky than leaving a port open, and advises removing access that is no longer needed. First determine whether the issue is actually inbound traffic, which network profile is active and whether the app itself is trustworthy. Then create the narrowest rule that works and retest from the intended network.
Before you start
Record the app path, publisher, required network profile and exact connection error. Confirm the PC is on the intended Private or Public network and that a VPN is not changing routing. Keep a way to manage the PC locally if editing rules remotely. On a managed device, request the approved change from IT.Do it step by step
- Open Windows Security > Firewall & network protection and confirm the firewall is enabled for the active network profile. Do not turn it off to test an unknown installer.
- Identify whether the app needs inbound listening, outbound access or only a server address correction. Test DNS and the app's own service status first.
- If inbound access is legitimate, open Allow an app through firewall, choose Change settings and select the exact trusted executable. Enable only the profile required for the use case.
- Use an explicit port rule only when the vendor documents a fixed port and an app rule cannot meet the need. Restrict its profile and, where appropriate, remote address scope.
- Test the connection from the expected peer, then test that unrelated networks do not gain access. Record the rule name, purpose and owner.
- Remove the rule when the app is uninstalled or no longer needs inbound access. Review old firewall exceptions during periodic maintenance.