Allow Remote Desktop Services and Ping Through Firewall on Windows Server 2008 R2 or Windows 7


This post in in response to questions on how to turn maintain remote connectivity to a server running Hyper-V with the firewall enabled.  The first thing to consider is what inbound traffic you want to enable on the server.  If it is a Hyper-V server you should consider if you are just going to use Remote Desktop (RDP / mstsc), SCVMM or Remote management to connect to it.  There are white papers written on how to enable remote administration and how to setup SCVMM to remotely connect to a Hyper-V server so I will just leave you with a reference to those and give you the step-by-step for establishing connectivity to the server using PING and Remote Desktop Client.

I am a fan of having ICMP (ping) enabled on all servers so the first thing I will cover is adding the ICMP allow rule.  We will then just enable the existing rule for Remote Desktop.  

To create a firewall rule for a server Create Firewall Rules in Windows Server 2008 or Windows Server 2008 R2 to allow RDP and ICMP traffic for your servers (same procedure for Windows 7) you have to open “Windows Firewall with Advanced Security” control panel applet.  You can get here by typing “firewall” in the search box near the start button and selecting it from the list (likely on top) or you can go to control panel.

Start – Control Panel – System and Security – Windows Firewall – Advanced Settings

Windows Firewall with Advanced Security

This will bring up the Windows Firewall with Advanced Security Screen. 

Click on Inbound Rules

image

The easy way to allow Ping is to enable the existing ICMP rules.

Enable ICMP (PING) Existing Rule(s)

You could scroll down and select File and Printer Sharing (Echo Request – ICMPv4-in) – Right Click and Select Enable Rule (Notice you will have one for multiple networks, you can enable the only the Domain network if you are in a domain environment or enable both if you want to enable on private networks also.

Notice there are ICMPv4 and ICMPv6.  If you are using (or plan on using) IPv6 on your network, I would encourage you to “enable” the IPv6 rules as well.

You could also Create a Rule from Scratch but if you do that the default action will be to enable all ICMP traffic instead of just enabling echo requests.  If you want to do that… Create a new rule click on New Rule in the Actions pane (upper right corner) or right click on Inbound Rule and select New Rule.  Select Custom – All Programs – for Protocol select ICMPv4. If you only want to do Echo Requests you will have to click on Customize, select Specific ICMP Types and Enable only Echo Request.  Scope leave at Any Action Leave at Allow the connection. Profile Select the networks you want to have it enabled  (usually Domain) and turn off the ones you do not want to have (usually public). Finally on the Name page of the wizard give it a name like (Allow Ping) and click Finish.   If you scroll to the top of the inbound rules, you should see your new rule there.

 

Enable Remote Desktop (mstsc) Existing Rule

You could scroll down and select Remote Desktop (TCP-In) – Right Click and Select Enable Rule (Notice you will have one for multiple networks, you can enable the only the Domain network if you are in a domain environment or enable both if you want to enable on private networks also. 

image

If you want to manually create your own rule, you would use the Predefined: Remote Desktop application or open the TCP Port 3389.

If you want to do Remote Administration on your Hyper-V Server you might also want to check out

Install and Configure Hyper-V Tools for Remote Administration.

If you have System Center Virtual Machine Manager (SCVMM) and you want to enable management of that the easy way to do it is to mount the SCVMM ISO or insert  the DVD and run the client application.  It can enable Hyper-V if needed and it can also setup all your firewall rules for you.

If your box is actually the SCVMM machine it is far more complicated. Check out SCVMM and Network Ports We Use for Communication

Comments (6)

  1. Anon says:

    What about IPv6?

  2. Zade says:

    its just below it v6-in!

  3. no3gods says:

    Create a firewall rule for new port:

    Open Windows Firewall with Advanced Security
    Create a new rule
    Select "Inbound Rules" on the top left
    Right-click and select "New Rule…"
    A new "Inbound Rule Wizard" window opens
    Select "Program"
    click Next
    Select “This program path:”
    Type System in the text field
    Click Next
    Select “Allow the connection”
    Click Next
    Choose the profiles that the rule is for
    Click Next
    Name the new rule
    I would use something like “RDP3390” or whatever the new port number is
    Click "Finish"
    Test your port by going to http://www.whatsmyip.org and use their port scanner. You should be able to turn the rule off and off the scan fail.

  4. Nilanjan Saha says:

    I faced similar problem today for a standalone Windows 2012 R2 system. My objective was to block all incoming connection and allow only incoming RDP to the system. Hence I created a New Incoming rule for blocking all traffic which worked as it should.
    Then I enabled the existing rule for RDP but couldnt connect even when all other settings are correct.

    Then after lots of failed attempts as suggested by many, I created two Incoming block rules i.e. first rule for TCP 0-3388 and second rule for TCP 3390-65535, thus only allowing port 3389 and this solved the problem.

    This is definitely a Bug which do not allow any rule to bypass Block All rule base. This needs to be fixed.

  5. show box says:

    Thanks for the great info. I really loved this. I would like to apprentice at the same time as you amend your web site, how could i subscribe for a blog site?
    For more info on showbox please refer below sites:
    http://showboxandroids.com/showbox-apk/
    http://showboxappandroid.com/
    Latest version of Showbox App download for all android smart phones and tablets.
    http://movieboxappdownloads.com/ – It’s just 2 MB file you can easily get it on your android device without much trouble. Showbox app was well designed application for android to watch movies and TV shows, Cartoons and many more such things on your smartphone.
    For showbox on iOS (iPhone/iPad), please read below articles:
    http://showboxappk.com/showbox-for-ipad-download/
    http://showboxappk.com/showbox-for-iphone/
    Showbox for PC articles:
    http://showboxandroids.com/showbox-for-pc/
    http://showboxappandroid.com/showbox-for-pc-download/
    http://showboxforpcs.com/
    There are countless for PC clients as it is essentially easy to understand, simple to introduce, gives continuous administration, effectively reasonable. it is accessible at completely free of expense i.e., there will be no establishment charges and after establishment
    it doesn’t charge cash for watching films and recordings.
    http://www.showboxforipad.org/showbox-apk/ Not simply watching, it likewise offers alternative to download recordings and motion pictures. The accompanying are the strides that are to be taken after to introduce Showbox application on Android. The above
    all else thing to be done is, go to the Security Settings on your Android telephone, Scroll down and tap on ‘Obscure sources’.
    http://www.showboxforipad.org/
    http://movieboxappdownloads.com/moviebox-apk-android/
    http://movieboxappdownloads.com/download-moviebox-pc/
    Movie Box, an esteemed movies application in which you can find stacks of programs and films. The guide is given here to download Movie Box app to Android and to Apple iOS 9.0.2, iOS 8.4/8.3 and also for the lower versions without Jailbreak.
    http://showboxforiphone.org/
    Please do login to Showbox application with the help of Ymail. You can login in Ymail from here –
    http://ymaillogintips.com/
    Sign Up & Do registration for latest movies on Showbox application

  6. Dad says:

    Thanks for the great info. I really loved this. I would like to apprentice at the same time as you amend your web site, how could i subscribe for a blog site?

    http://www.movieboxapkdownload.com/ – It’s just 2 MB file you can easily get it on your android device without much trouble. Showbox app was well designed application for android to watch movies and TV shows,
    Cartoons and many more such things on your smartphone.
    http://www.aptoideapkdownload.com/ – It’s just 2 MB file you can easily get it on your android device without much trouble.

    http://www.vidmatedownloadapk.com/

    Showbox app was well designed application for android to watch movies and TV shows, Cartoons and many more such things on your smartphone.

    http://www.shareitforpccdownload.com/

    http://www.shareitforpccdownload.com/shareit-for-pc-windows-10-8-1-7-mac-free-download/

    SHAREit for PC lets you transfer files between devices like phones, tablets and computers. With the wide area of sharing compatibility, sharing across anything is easy now. This is the best and the fastest alternative for USB sharing.