Règles sortantes sur Windows Server (Pare-feu — Partie 2)
Bloquer ou restreindre le trafic sortant : politique par défaut, règles Outbound, liste blanche et diagnostic.
Partie 1 : entrant. Ici : sortant. Par défaut Windows Server laisse tout sortir — pratique mais risqué.
Vidéo : Configurez votre premier pare-feu — Partie 2/2 — YouTube
1. Politique par défaut
wf.msc > Windows Defender Firewall Properties. Outbound = Allow par défaut. Passer à Block ⇒ liste blanche obligatoire.
2. Règle Outbound bloquante (assistant)
Outbound Rules > New Rule… > Port > TCP 25 > Block. Exemple : bloquer SMTP sortant.
3. PowerShell — bloquer
New-NetFirewallRule -DisplayName "Block SMTP out" -Direction Outbound -Protocol TCP -RemotePort 25 -Action Block
Vers une IP : -RemoteAddress 198.51.100.42 -Action Block.
4. Par programme
-Program "C:\App\update.exe" -RemoteAddress 203.0.113.10 -Action Allow.
5. Whitelist (default-deny)
- Allow DNS 53, NTP 123, HTTPS 443, HTTP 80 si besoin.
- Allow par programme pour vos binaires.
- Outbound default = Block.
- Redémarrer et vérifier.
6. Diagnostic
Test-NetConnection www.fusiora.com -Port 443Get-NetFirewallRule -Direction OutboundSet-NetFirewallProfile -LogBlocked Truepktmon start -c+pktmon format
7. Pièges
- DNS bloqué → tout casse.
- Windows Update : *.windowsupdate.com 443.
- Activation : KMS TCP 1688.
- Agent de monitoring : Allow par programme.
Politique sortante bien conçue limite les dégâts. Combinez avec la Partie 1 et le pare-feu Fusiora.
Cet article vous a-t-il été utile ?
Soyez le premier à le noter