What Port/Prgrm to open for Defender and Windows Update

  • Thread starter Thread starter Pit
  • Start date Start date
P

Pit

Guest
Hi there,

I have my (windows) firewall configured to block outgoing traffic except
for given rules that are in place. Works perfect and blocks unwanted
incoming and outgoing traffic alike.

The problem is that from activating the firewall neither Windows
Defender updates nor Windows Update are working anymore. On the one hand
this is proof that the firewall works but these comm is wanted.

I did not find any hints in the internet what prog and/or port has to be
allowed for outginig traffic to get this to working again.

Any ideas here?

Pit
 
RE: What Port/Prgrm to open for Defender and Windows Update

For Windows Defender, Ports 80 and 443, same as the ones needed to do Windows
Updates.
-

"Pit" wrote:

> Hi there,
>
> I have my (windows) firewall configured to block outgoing traffic except
> for given rules that are in place. Works perfect and blocks unwanted
> incoming and outgoing traffic alike.
>
> The problem is that from activating the firewall neither Windows
> Defender updates nor Windows Update are working anymore. On the one hand
> this is proof that the firewall works but these comm is wanted.
>
> I did not find any hints in the internet what prog and/or port has to be
> allowed for outginig traffic to get this to working again.
>
> Any ideas here?
>
> Pit
>
 
Re: What Port/Prgrm to open for Defender and Windows Update

Engel schrieb:
> For Windows Defender, Ports 80 and 443, same as the ones needed to do Windows
> Updates.
> -


Thanks for the hint, will try this. But best would be to configure not
just a port but also the prog. Otherwise trojans could use the
unspecific opened ports to send informations home.

Do you know what exe does the updates?

Pit
 
Re: What Port/Prgrm to open for Defender and Windows Update

Pit schrieb:
> Engel schrieb:
>> For Windows Defender, Ports 80 and 443, same as the ones needed to do Windows
>> Updates.
>> -

>
> Thanks for the hint, will try this. But best would be to configure not
> just a port but also the prog. Otherwise trojans could use the
> unspecific opened ports to send informations home.


Now I found the solution. The process used is svchost.exe. For this prog
both of the ports have to be opened. After that all works fine. You'll
get a warning when defining rules against svchost.exe but this warning
can be ignored.

Pit
 
Back
Top