Check Firewall Status in Windows 11 and 10: Windows Security, netsh, PowerShell and Fixes
To check your firewall status in Windows 11, open Windows Security from the Start menu and select Firewall & network protection. It lists the three network profiles, Domain network, Private network and Public network, and says Firewall is on or off for each, with the active profile marked. If another security product manages your firewall, its name appears there instead. From Command Prompt, netsh advfirewall show allprofiles state shows the same on or off status for each profile, and in PowerShell, Get-NetFirewallProfile | Select-Object Name, Enabled does too. If the firewall is off for the profile you are using, turn it on from the same Windows Security page. A firewall that will not turn on usually means a stopped service, a policy, or a third-party product in control.
Ethan's son installed a game server tool on the family PC, and a forum post told him to "just turn off the firewall" to let friends connect. A week later, Ethan wondered whether the firewall was still off. Jake opened Windows Security and there it was: the Private network profile showed Firewall is off, with a red warning, while Public was still on. He turned the private firewall back on, then added a single rule allowing the game server through, which was all the forum had really needed. Ethan now checks the firewall page whenever someone installs something new, and his son has learned that "turn off the firewall" in a forum post usually means "add one rule". This page shows every way to check firewall status in Windows 11 and 10, what the profiles mean, how to check a remote PC, and what to do when the firewall is off and will not turn back on.
What the Windows firewall does, and why its status matters
The firewall built into Windows, called Microsoft Defender Firewall, decides which network connections are allowed into and out of your PC. By default it blocks unsolicited incoming connections, such as another device on the network trying to reach a service on your PC, while allowing the connections your apps start themselves, like web browsing and email. Apps that need to accept incoming connections, such as games that host matches or file sharing, ask for permission through a rule, which Windows usually prompts you about the first time.
That default protects you most on networks you do not control: cafes, hotels, airports and shared buildings, where other devices may be hostile or infected. At home, behind a router, it is a second layer behind the router's own protection, and it still matters, because a single infected device on your home network can attack the others. A firewall that is off leaves every listening service on the PC open to anything on the same network.
Many people are surprised how many programs listen for connections: media sharing, game launchers, remote support tools, printer software, development servers and more. Each is fine behind a firewall that only lets in what you have allowed, and each is a possible way in when the firewall is off. That is the practical case for checking status regularly, rather than assuming the firewall is on because it was on last year.
The firewall gets turned off more often than people realize: by troubleshooting advice like the forum post Ethan's son followed, by some older programs during installation, by tweak tools, by third-party security suites that replace it, or by malware. Checking its status takes ten seconds, which is why it is worth knowing how.
It also helps to know that the firewall can be on and still allow something you did not expect, because of a rule added by an app. Status tells you the firewall is working; rules tell you what it lets through. For most home users, checking status regularly and reviewing allowed apps occasionally covers both. The sections below show how to do each, from the ten-second check to the detailed view.
Firewall, antivirus and router: what each protects
People often mix up the firewall with antivirus, or assume the router makes the PC's firewall unnecessary. They do different jobs. The Windows firewall controls network connections to and from the PC, blocking unwanted incoming connections and, with rules, specific outgoing ones. Microsoft Defender Antivirus examines files and programs for malware, whether they arrive by download, USB drive or email. The router separates your whole home network from the internet, mostly by not forwarding unsolicited connections from outside.
Each covers gaps the others leave. The router does nothing about another infected device inside your home, or about public Wi-Fi when you travel. The firewall does nothing about a malicious file you open yourself. Antivirus does not stop a service on your PC from being reached over the network. That is why Windows Security shows them together and why turning any one off, even when the others are on, leaves a real gap. Checking the firewall status is one third of a quick security check; the virus and threat protection page covers the second, and your router's settings the third.
Check firewall status in Windows Security
- Open the Start menu, type Windows Security, and open it. Or open Settings, Privacy & security, Windows Security, then Open Windows Security.
- Select Firewall & network protection in the left menu or on the home page.
- Read the three profiles: Domain network, Private network and Public network. Each says Firewall is on or Firewall is off, and the profile your current network uses is labeled (active).
A green check means that profile's firewall is on. A red or yellow warning, with a Turn on button, means it is off; select Turn on and approve the prompt to fix it. If the page says a different product, such as a third-party security suite, is managing your firewall, Windows' own firewall is turned off on purpose and that product is protecting you instead; check its status in that product's window. On the Windows Security home page, the firewall tile also shows a summary, so a green check there means all is well.
Checking from the taskbar is even quicker: the Windows Security shield near the clock shows a small yellow or red mark when something, including the firewall, needs attention. If the shield has no mark, the firewall is on for the profile in use. Selecting the shield opens Windows Security straight to the overview, from which the firewall page is one click away.
In Windows 10, the steps are the same: Windows Security, Firewall & network protection. The older Control Panel page, Windows Defender Firewall, still exists in both versions and shows a simple on or off status with green or red shields for private and public networks; search the Start menu for Windows Defender Firewall to open it.
This table compares every way to check the status, so you can pick the one that suits the moment.
| Method | How to open | Shows | Admin needed to read? |
|---|---|---|---|
| Windows Security | Start, Windows Security, Firewall & network protection | On or off per profile, active profile, third-party product | No |
| Control Panel | Search Windows Defender Firewall | On or off for private and public | No |
| Advanced console | wf.msc in the Run box | Profiles, every rule, monitoring | Yes, to open |
| Command Prompt | netsh advfirewall show allprofiles state | ON or OFF per profile | No |
| PowerShell | Get-NetFirewallProfile | Enabled per profile, plus settings | No |
Domain, Private and Public: the firewall profiles explained
Windows keeps three separate firewall settings, called profiles, and applies one depending on the network you are connected to. Each can be on or off independently, which is why Ethan's PC could have the private firewall off while the public one stayed on.
| Profile | Used for | Default behavior | Should it be on? |
|---|---|---|---|
| Domain network | Work networks where the PC is joined to the organization's domain | Rules set by the organization | Yes; usually managed by IT |
| Private network | Trusted networks you mark as private, such as home | Allows device discovery and file and printer sharing if enabled | Yes |
| Public network | Cafes, hotels, airports, and any network you mark as public | Most restrictive; hides the PC from other devices | Always |
Which profile applies depends on how the network is set in Windows. When you first join a network, Windows asks whether to make the PC discoverable; that choice sets the network as private or public. You can change it in Settings, Network & internet, the Wi-Fi or Ethernet properties, Network profile type. If your home network is set to Public, everything stays protected but sharing between your devices may not work; if a public network is set to Private, your PC is more exposed than it should be.
The active profile is the one that matters at any moment. Check which is active on the Windows Security firewall page, then make sure that profile's firewall is on. All three should normally be on; the only common exception is the Domain profile on PCs not joined to a domain, where it simply never applies.
A quick way to remember the profiles: Public is for anywhere you would not leave your bag unattended, Private is for home, and Domain is for the office network your employer controls. If your laptop moves between all three, Windows switches profiles automatically as you connect to each network, applying the right level of protection without you doing anything, as long as each network was set to the right type when you first joined it.
Firewall, file sharing and network discovery
A common reason people suspect the firewall is that file or printer sharing between home PCs does not work. The firewall allows sharing only on networks set as Private, and only when network discovery and file and printer sharing are turned on for that profile. On a home network mistakenly set as Public, sharing fails even with the firewall on, because the public profile hides the PC.
The fix is not to turn the firewall off but to set the home network to Private in its properties, and then turn on network discovery and file sharing under Settings, Network & internet, Advanced network settings, Advanced sharing settings. Windows enables the matching firewall rules automatically. Leave these off for public networks. This is one of the cases where checking the firewall status reveals a profile mistake rather than a firewall problem.
Check firewall status with Command Prompt
For a quick text answer, or for checking from a script, use the netsh command. Open Command Prompt and run:
netsh advfirewall show allprofiles state
The output lists Domain Profile Settings, Private Profile Settings and Public Profile Settings, each with a State line reading ON or OFF. Leave off the word state at the end to see more detail for each profile, including the default inbound and outbound policy, whether notifications are shown, and logging settings. netsh advfirewall show currentprofile shows only the profile in use right now.
To turn the firewall on for all profiles from an administrator Command Prompt, run netsh advfirewall set allprofiles state on. Our guide to running Command Prompt as administrator shows how to open the right kind of window. Reading the status works in a normal window; changing it needs administrator rights.
The netsh output is also handy for support: copying it into a message gives a helper an exact picture of the firewall settings in a few lines, without screenshots. If a profile shows State ON but an app still cannot connect, the problem is a rule, not the firewall being off, and the advanced console is where to look next. If a profile shows OFF and you did not turn it off, check the event log described further down to see what did.
Windows 11 Home and Pro: same firewall, different controls
Windows 11 Home and Pro include exactly the same firewall, with the same profiles, rules and protection. The differences are in management tools. Pro, Enterprise and Education include Group Policy, where administrators can enforce firewall settings under Computer Configuration, Administrative Templates, Network, Network Connections, Windows Defender Firewall, or under Windows Settings, Security Settings, Windows Defender Firewall with Advanced Security. Home users manage the same settings through Windows Security, wf.msc, netsh and PowerShell.
Enforced policies are what make the firewall settings gray out with a managed by your organization message. On a work PC that is expected. On a home PC running Home, a grayed out firewall usually points to a tweak tool or leftover settings written directly to the registry, which resetting the firewall to default or removing the leftover policy values clears.
Check firewall status with PowerShell
PowerShell gives the same information in a form that is easy to filter and use in scripts. Run:
Get-NetFirewallProfile | Select-Object Name, Enabled
Each profile appears with Enabled set to True or False. To see more, such as the default actions and logging settings, run Get-NetFirewallProfile on its own. To turn the firewall on for all profiles, run Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled True in PowerShell as administrator.
To see which profile your network connection is using, run Get-NetConnectionProfile and look at the NetworkCategory line, which reads Public, Private or DomainAuthenticated. Combining the two tells you exactly which firewall profile is protecting your current connection and whether it is on.
For a quick report you can save, run Get-NetFirewallProfile | Format-Table Name, Enabled, DefaultInboundAction, DefaultOutboundAction, which shows each profile with its default actions. Normal values are Block for inbound and Allow for outbound. An inbound default of Allow means the firewall is effectively letting everything in for that profile, even though it reports as enabled, which some tweak tools do and which is worth correcting by restoring defaults.
Check the firewall status of another PC
IT staff and people looking after several family PCs sometimes need to check another PC's firewall without walking over to it. With PowerShell remoting enabled on the target PC, which is common on managed networks, run Invoke-Command -ComputerName PCNAME -ScriptBlock { Get-NetFirewallProfile | Select-Object Name, Enabled } from an administrator PowerShell, using the other PC's name. You need an administrator account on that PC.
On managed networks, the organization's management tools and Microsoft Defender's security dashboards show firewall status for every device centrally, which is more practical than checking one at a time. On a home network without remoting set up, the simplest method is to check on each PC, or use Remote Desktop or a remote support tool to reach it. A firewall that blocks remote management can also block these checks, which is by design.
The firewall and Remote Desktop
Turning on Remote Desktop in Settings, System, Remote Desktop automatically enables the firewall rule that lets Remote Desktop connections in, on the appropriate profiles. If Remote Desktop works on the home network but not elsewhere, the firewall profile and the router are the likely reasons, and that is usually a good thing: exposing Remote Desktop directly to the internet is a common way PCs get attacked. For access from outside, use a VPN or a remote access service rather than opening Remote Desktop to the world.
When Remote Desktop does not connect even on the home network, check that the Remote Desktop rules are enabled in wf.msc for the Private profile, and that the network is set as Private. Our guide to turning Remote Desktop on or off covers the full setup on both ends.
The firewall is off and will not turn on
If the Turn on button does nothing, the setting reverts, or Windows Security shows an error, work through these causes. A third-party security product may control the firewall: check whether one is installed, and either use its firewall or uninstall it with its removal tool to give control back to Windows. A policy may enforce the setting: on work PCs this is deliberate, and on home PCs it can be left behind by tweak tools; the message "Some settings are managed by your organization" is the clue, and our guide to "managed by your administrator" in Windows Security covers removing leftover policies.
The firewall service may be stopped. Press Windows + R, type services.msc, find Windows Defender Firewall, and make sure its startup type is Automatic and it is running. If it will not start, our guide to the firewall service that cannot start covers the dependencies and repairs, and our guide to error 0x800706d9 covers the most common error code. If settings are scrambled, resetting the firewall to default restores the original rules and turns it back on.
Finally, malware sometimes turns the firewall off and keeps it off. If you did not turn it off and nothing above explains it, run a full scan with Microsoft Defender, including an offline scan, before turning it back on; our guide to scanning with Microsoft Defender shows how.
Once you have found the cause, turning the firewall back on safely follows a short routine that avoids breaking the app that needed the firewall off in the first place.
- Note which app or task needed the firewall off, if any.
- Turn the firewall on for all profiles in Windows Security, or with netsh advfirewall set allprofiles state on.
- Test the app. If Windows asks whether to allow it, choose Private networks only.
- If the app still does not work, add a rule for it under Allow an app through firewall.
- Check the status again after a restart to confirm it stays on.
This routine is what Jake used on Ethan's family PC: firewall on, then one rule for the game server, then a restart to confirm. The whole thing took five minutes and left the PC fully protected.
Allow an app instead of turning the firewall off
The most common reason people turn the firewall off is to make one app work: a game server, a file sharing tool, a remote access program or a media server. Turning off the whole firewall for one app is like leaving the front door open because one guest needed to get in. The right fix is a rule for that app.
In Windows Security, Firewall & network protection, select Allow an app through firewall, then Change settings, find the app or select Allow another app to browse to it, and check Private, and Public only if needed. Our guide to allowing or blocking an app through the firewall covers it step by step, including advanced port rules. That is exactly what fixed Ethan's son's game server: one rule for the server program on the private network, with the firewall back on everywhere else.
When you allow an app, choose the narrowest setting that works. Private only is right for most home uses, such as game servers, media servers and file sync between your own devices. Public should be reserved for apps that truly need incoming connections on untrusted networks, which is rare for home users. And if an app asks for permission and you do not recognize it, deny it; you can always allow it later if something you use stops working.
The firewall and online games
Gamers are the group most often told to turn off the firewall, and almost never need to. Most online games make outgoing connections to game servers, which the firewall allows by default. When a game or launcher wants to accept incoming connections, for example to host a match or for voice chat, Windows asks the first time; choosing Allow on Private networks creates the rule it needs. Problems that look like firewall issues in games are more often the router: strict NAT types, blocked ports or UPnP being off, which affect connections from outside your home, not the Windows firewall.
If a game does have a firewall problem, the game's support pages usually list the exact program or ports to allow, and a single rule fixes it permanently. Running a game server for friends, as Ethan's son wanted to, needs that rule on the PC and, for friends outside your home, a port forward or a hosting service on the router side. Neither requires the firewall to be off.
Consoles and handheld gaming PCs on the same network have their own settings, but a Windows gaming PC acting as a host for them follows the same rules: allow the specific program, keep the firewall on, and look at the router for anything involving players outside your home. When a game works for you but not for a friend joining from elsewhere, the router is almost always the place to look, not the Windows firewall.
The firewall and VPNs
VPN apps add their own network adapter, and Windows assigns it a network profile like any other connection, usually Public. That can affect firewall behavior while the VPN is connected, such as blocking file sharing that works without the VPN. Some VPN apps also include a kill switch that uses firewall rules to block traffic if the VPN drops, which can look like the firewall blocking everything when the VPN is disconnected.
If connections fail only with the VPN on, check the VPN adapter's profile in Settings, Network & internet, and the VPN app's own settings for local network access and kill switch options, rather than turning the Windows firewall off. Work VPNs often have firewall policies set by IT, which should be left to them.
How to tell if the firewall is actually working
On means enabled, but you may want evidence that it is blocking what it should. The firewall can keep a log: in the Windows Defender Firewall with Advanced Security console, opened by typing wf.msc in the Run box, open the properties for a profile, and under Logging set Log dropped packets to Yes. Windows then records blocked connections in %SystemRoot%\System32\LogFiles\Firewall\pfirewall.log, a text file you can open in Notepad. Seeing dropped entries there shows the firewall is doing its job.
A simpler sign is the prompt that appears when a new app tries to accept connections, asking whether to allow it; that prompt comes from the firewall, and seeing it means the firewall is on and working. Online port check websites can test whether ports are open from the internet, but they mainly test your router, since most home PCs sit behind one. For a laptop on public Wi-Fi, the firewall's public profile is the main protection, and checking that it is on is the key test.
Find out when the firewall was turned off
If you discover the firewall is off and want to know when it happened, or what did it, Windows keeps a record. Open Event Viewer, go to Applications and Services Logs, Microsoft, Windows, Windows Firewall With Advanced Security, and select Firewall. The log records changes to firewall settings, including profiles being turned on or off and rules being added, changed or deleted, with the time and, often, the program that made the change.
Scrolling to around the time the firewall changed usually tells the story: an installer adding rules and changing a setting, a tweak tool switching profiles off, or a person doing it through Windows Security. On Ethan's family PC, the log showed the private profile turned off on the evening the game server tool was installed, which matched the forum advice exactly. If the log shows changes you cannot explain, and especially repeated changes back to off after you turn it on, treat it as a sign of malware and scan the PC.
The advanced firewall console
For more than on and off, Windows includes Windows Defender Firewall with Advanced Security. Open it by typing wf.msc in the Run box, or from Windows Security, Firewall & network protection, Advanced settings. The main page shows each profile's status and default behavior. Inbound Rules and Outbound Rules list every rule, enabled rules marked with a green check, blocking rules with a red symbol. The Monitoring node shows the active profile and which rules are currently in effect.
The console is where you can see exactly why an app can or cannot connect: search for its name in the rules list, and check whether its rule is enabled, for which profiles, and whether it allows or blocks. It is also where to clean up after old apps, which often leave rules behind when uninstalled. Disable or delete rules for programs you no longer use, since a forgotten allow rule for an old program is an opening nobody is watching. Sorting the rules list by name or by program makes leftovers easy to spot, and disabling a rule first, rather than deleting it, lets you undo the change if something stops working. Be careful not to delete Windows' own rules, which have names like Core Networking or File and Printer Sharing; disabling the wrong one can break networking. If things go wrong, restoring defaults puts every rule back.
Block an app from the internet with an outbound rule
By default, the Windows firewall allows outgoing connections, so any app you run can reach the internet. Sometimes you want to stop one: an old program that phones home, an app that should work offline, or a game you do not want updating. An outbound rule does it. In wf.msc, select Outbound Rules, New Rule, choose Program, browse to the app's .exe file, choose Block the connection, select the profiles, and name the rule.
The app can no longer connect out, while everything else continues normally. To undo it, disable or delete the rule. Outbound rules are a precise tool, much better than turning the firewall off or blocking whole categories, and checking the firewall status page does not show them, so keep a note of any you create.
Firewall notifications and warnings
Windows shows a notification when the firewall is turned off, and a red or yellow mark on the Windows Security icon near the clock. If you turned the firewall off deliberately for testing, those warnings remind you to turn it back on, which is useful. If you see them unexpectedly, check the status as described above, because something turned it off.
The notification asking whether to allow an app is also part of the firewall. It appears the first time a program tries to accept incoming connections. Allow it only for programs you trust and recognize, and only on private networks unless the program truly needs public access. If you clicked the wrong option, you can change it later in Allow an app through firewall. You can turn these notifications on or off per profile in Firewall & network protection, Firewall notification settings, but leaving them on is wiser.
Firewall myths
Several common beliefs lead people to turn the firewall off unnecessarily. The firewall slows down the internet: on modern PCs, the Windows firewall's effect on speed is negligible; slow internet has other causes. Games need the firewall off: they need, at most, one allow rule, as described above. The router makes the firewall pointless: the router does not protect you from other devices on your network or on public Wi-Fi. Antivirus includes a firewall: Microsoft Defender Antivirus does not; the firewall is a separate component, though both appear in Windows Security.
A firewall stops all hacking: it does not stop malware you download and run yourself, phishing, or attacks through apps you have allowed; it is one layer among several. And turning it off briefly is harmless: it often stays off far longer than intended, as on Ethan's family PC, where a quick test turned into a week. If you turn it off to test something, set a reminder to turn it back on, or better, use a rule for the specific app instead.
A two-minute monthly security check
Checking the firewall fits naturally into a short routine that catches most problems early. Once a month, open Windows Security and look at the home page: every tile should show a green check, including Virus & threat protection, Firewall & network protection, and Device security. Then open Windows Update and install anything waiting. Finally, glance at Settings, Apps, Startup for programs you do not recognize.
Anything with a yellow or red mark gets attention the same day. The firewall tile turning red is often the first visible sign that something changed a setting without you knowing, whether a new program, a family member following advice online, or, rarely, malware. Ethan put the check on his calendar for the first Sunday of each month, and it takes him less time than making a coffee.
Third-party firewalls and security suites
Some paid security suites include their own firewall, and when installed they register with Windows Security and take over firewall duty, turning Windows' firewall off. Windows Security then shows that product's name on the firewall page instead of the three profile statuses. In that case, check the status in the suite's own window, and make sure its subscription is active, because an expired suite can leave you with no working firewall at all.
If you uninstall such a suite, Windows should turn its own firewall back on automatically. Check the firewall page afterward to be sure, and use the suite maker's removal tool if remnants keep Windows from taking over. For most home users, Microsoft Defender Firewall is entirely adequate, and using it avoids the expired-subscription trap. Our guide to real-time protection covers the antivirus side of the same handover.
Windows 10: the same firewall
Windows 10 uses the same Microsoft Defender Firewall with the same three profiles, and every check on this page works identically: Windows Security, Control Panel, wf.msc, netsh and PowerShell. Since October 2025, Windows 10 only receives security fixes on PCs enrolled in Extended Security Updates, and for home users those run until October 2027. On a Windows 10 PC no longer receiving updates, the firewall becomes even more important, since unpatched services are easier to attack; keep it on, keep the public profile for any network you do not control, and avoid exposing services to the internet.
Frequently asked questions
How do I check if my firewall is on in Windows 11?
Open Windows Security, select Firewall & network protection, and read the status for Domain, Private and Public networks. Firewall is on with a green check means it is working; the active profile is labeled.
What is the command to check firewall status?
In Command Prompt, run netsh advfirewall show allprofiles state. In PowerShell, run Get-NetFirewallProfile | Select-Object Name, Enabled.
How do I check firewall status in Windows 10?
Open Windows Security, Firewall & network protection, or the Windows Defender Firewall page in Control Panel. The commands also work the same in Windows 10.
How do I turn on Windows Firewall?
In Windows Security, Firewall & network protection, select Turn on for each profile that is off. From an administrator Command Prompt, run netsh advfirewall set allprofiles state on.
Why is my Windows Firewall off?
Someone turned it off, often to make an app work; a third-party security product replaced it; a tweak tool or policy disabled it; or malware turned it off. Check for a third-party product and scan for malware if you did not turn it off.
Why will Windows Firewall not turn on?
A third-party product controls it, a policy enforces it, or the Windows Defender Firewall service is stopped. Check the service, remove leftover policies, or reset the firewall to default.
What is the difference between private and public network in the firewall?
Private is for trusted networks like home and allows sharing if enabled; Public is for untrusted networks and is more restrictive. Each has its own firewall setting.
Which firewall profile am I using?
Windows Security marks the active profile on the Firewall page. In PowerShell, Get-NetConnectionProfile shows the NetworkCategory of your connection.
Should all three firewall profiles be on?
Yes. The Domain profile only applies on work domains, but leaving all three on is the safe default.
How do I check firewall status on a remote computer?
Use Invoke-Command -ComputerName PCNAME -ScriptBlock { Get-NetFirewallProfile } from an administrator PowerShell, with remoting enabled and admin rights on the target.
How do I know if my firewall is blocking something?
Turn on logging for dropped packets in wf.msc and check pfirewall.log in System32\LogFiles\Firewall. Apps blocked by the firewall usually trigger a prompt the first time.
Do I need Windows Firewall if I have a router?
Yes. The router protects against the internet, but the Windows firewall protects against other devices on the same network and on public Wi-Fi.
Is it safe to turn off the firewall to play a game?
No need. Allow the game through the firewall instead, on private networks only, and keep the firewall on.
Does a third-party antivirus replace Windows Firewall?
Some security suites include their own firewall and turn Windows' off; Windows Security then names that product. Others work alongside Windows Firewall. Either way, one firewall should be on.
How do I check firewall settings in Windows 11?
Windows Security, Firewall & network protection shows status and links to allowed apps, advanced settings and resetting defaults. The advanced console, wf.msc, shows every rule.
Why does Windows say some settings are managed by your organization?
A policy controls the firewall. On work PCs, IT sets it. On home PCs, it may be left by a tweak tool or old work management and can be removed.
What does Firewall is off mean in Windows Security?
The firewall for that network profile is disabled, leaving the PC more exposed on that type of network. Select Turn on unless a trusted third-party firewall is in use.
How do I reset the firewall?
In Windows Security, Firewall & network protection, select Restore firewalls to default, or run netsh advfirewall reset in an administrator Command Prompt. Custom rules are removed.
How do I find out when the firewall was turned off?
Open Event Viewer, Applications and Services Logs, Microsoft, Windows, Windows Firewall With Advanced Security, Firewall. It records profile and rule changes with times, often with the program responsible.
Does the Windows firewall slow down my internet?
No meaningful amount on modern PCs. Slow connections have other causes, such as Wi-Fi signal, the router or the internet service.
Checking the firewall takes ten seconds and is worth doing whenever someone installs something new or follows troubleshooting advice from a forum. Look at the active profile in Windows Security, or run one command, turn the firewall back on if it is off, and allow the specific app that needed access instead. If it will not stay on, the service, a policy, a third-party product or the event log will tell you why. Ethan's family PC has its firewall on everywhere again, with one rule for the game server, and the forum's advice is a lesson learned.
📌 If you keep one line from this page
Windows Security, Firewall & network protection shows each profile; netsh advfirewall show allprofiles state shows the same in one line.
Need an app to work? Allow it through the firewall; do not turn the firewall off.
Revision note. Written October 3, 2026, expanding our 2016 guide to checking firewall status in Windows into a complete guide for Windows 11 and 10. It covers what the firewall does, Windows Security, the three profiles, Command Prompt and PowerShell checks, remote checks, a firewall that will not turn on, allowing apps, checking it works, and notifications. May every unwanted connection bounce off.