Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Allow or Block an IP Address in Windows Firewall

This guide shows how to add an IP address to Windows Firewall rules on a Windows computer or Windows server. It needs administrator rights.

Firewall2 min read18 steps9 screenshots

What is Windows Firewall?

A firewall is a guard that decides which connections may reach your computer. Windows Firewall comes with Windows. An IP address is a number that identifies a computer on a network, like a house number.

You may want to allow one trusted IP address, for example your office, to reach your Windows VPS. Or you may want to block an address that keeps attacking you.

Allow a single IP address

  1. Click Start and type Windows Defender Firewall with Advanced Security. Open it.
    Screenshot: Click Start and type Windows Defender Firewall with Advanced Security . Open it.
    Screenshot: Click Start and type Windows Defender Firewall with Advanced Security . Open it.
  2. On the left, click Inbound Rules. Inbound means traffic coming into your machine.
  3. On the right, click New Rule.
  4. Choose Port and click Next.
  5. Choose TCP. In Specific local ports, type the port you want, for example 3389 for Remote Desktop. Click Next.
  6. Choose Allow the connection and click Next.
  7. Tick Domain, Private and Public as needed. Click Next.
  8. Give the rule a name such as "Allow office IP". Click Finish.
  9. Double-click the new rule in the list.
  10. Open the Scope tab.
  11. Under Remote IP address, choose These IP addresses.
  12. Click Add, type the IP address, and click OK.
  13. Click OK again to save.

Now only that address can use the port.

Warning: If you change a Remote Desktop rule on a remote server, make sure your own IP address is in the list. Otherwise you can lock yourself out.

Block an IP address

  1. Create a new inbound rule as above.
    Screenshot: Create a new inbound rule as above.
    Screenshot: Create a new inbound rule as above.
  2. Choose Custom instead of Port, and accept the defaults until the Scope page.
  3. Under Which remote IP addresses does this rule apply to?, choose These IP addresses and add the address to block.
    Screenshot: Under Which remote IP addresses does this rule apply to? , choose These IP addresses and a
    Screenshot: Under Which remote IP addresses does this rule apply to? , choose These IP addresses and a
    Screenshot: Under Which remote IP addresses does this rule apply to? , choose These IP addresses and a
  4. On the Action page, choose Block the connection.
    win IP address firewall settings name
  5. Name it, for example "Block bad IP", and click Finish.
    win IP address firewall settings finish

Do it with one command

Open PowerShell as administrator and run:

New-NetFirewallRule -DisplayName "Block bad IP" -Direction Inbound -RemoteAddress 203.0.113.5 -Action Block

This creates a rule that blocks inbound traffic from the address 203.0.113.5. Replace it with the real address.

Tip: You can remove a rule any time. Right-click it in the list and choose Delete, or Disable Rule to keep it for later.

Need help? Open a support ticket.

Quick recap

  • Open Windows Defender Firewall with Advanced Security.
  • Create a new inbound rule.
  • Use the Scope tab to list the IP address.
  • Choose Allow or Block.
  • Keep your own IP allowed on remote servers.