Almost of the time wedesire our applications online and connected to both our local network and the greater Cyberspace. There are instances, however, when nosotros want to foreclose an awarding from connecting to the Internet. Read on as we show yous how to lock downward an application via the Windows Firewall.

Why Do I Desire To Do This?

Some of you might accept been sold immediately past the headline, every bit blocking an application is exactly what you've been wanting to do. Others may have opened this tutorial curious every bit to why one would block an application in the first place.

Although you generally want your applications to take free access to the network (after all what practiced is a web browser that can't reach the web) at that place are a diverseness of situations in which you lot may wish to preclude an application from accessing the network.

Some simple and commonplace examples are as follows. You might have an awarding that insists on automatically updating itself, but find that those updates intermission some functionality and yous want to stop them. You might have a video game that you're comfortable with your child playing, but you're non so comfortable with the online (and unsupervised) multiplayer elements. Yous might be using an application with really obnoxious ads that tin be silenced past cutting off the application's Net admission.

Regardless of why you want to drib the cone of network connectivity silence over a given application, a trip into the guts of the Windows Firewall is an piece of cake mode to do so. Let's take a look at how to block an application from accessing the local network and Internet now.

Creating a Windows Firewall Dominion

Although nosotros'll exist demonstrating this trick on Windows x, the basic layout and premise has remained largely unchanged over the years and you can easily adapt this tutorial to before versions of Windows.

To create a Window Firewall rule, y'all beginning demand to open the avant-garde Firewall interface, which is named, accordingly enough, Windows Firewall with Advanced Security. To do so navigate to the Control Panel and select "Windows Firewall." In the "Windows Firewall" window, click the "Avant-garde Settings" link on the left.

Note: At that place isa lot going on in the advanced interface and nosotros encourage you follow along closely, leaving annihilation outside the scope of the tutorial and your experience level solitary. Mucking up your firewall rules is a surefire way to a big headache.

In the far left navigation pane, click the "Outbound Rules" link This displays all the existing outbound firewall rules in the heart pane. Don't exist surprised that it is already populated with dozens and dozens of Windows-generated entries.

In the far right pane, click  "New Rule" to create a new rule for outbound traffic.

In the "New Outbound Dominion Wizard," confirm that the "Program" choice is selected, and then click the "Next" button.

On the "Program" screen, select the "This program path" option, and then blazon (or browse for) the path to the programme yous desire to block. For the purposes of this tutorial, we're going to block a portable copy of the Maxthon spider web browser—mostly because information technology will be easy to demonstrate to you that the browser is blocked. Merely, don't click "Next" just even so.

There'southward an important alter you need to make before you continue. Trust us on this. If yous skip this footstep you'll cease up frustrated.

When you use the "Browse" control to select an EXE file, Windows defaults to using what are known as environmental variables if the particular path includes a given path portion represented past one of those variables. For instance, instead of insertingC:\Users\Steve\, information technology will swap that portion for the environmental variable%USERPROFILE% .

For some reason, despite the fact that this is the default mode it populated the program path field,it will pause the firewall rule. If the file you lot take browsed to is anywhere that uses an environmental variable (like the/User/ path or the/Plan Files/ path), y'all have to manually edit the program path entry to remove the variable and supersede it with the correct and full file path. In case that's a tad confusing let us illustrate with our example programme from above.

When we browsed to the EXE file for our Maxthon spider web browser, Windows plugged in the following program path data for the file, which was located in our Documents folder:


That file path is understood by Windows, but for some reason is no longer recognized when inserted into a firewall rule. Instead, we need to replace the file path that includes the environmental variable with the full file path. In our case it looks like this:


Information technology's possible this is some quirk isolated to the electric current version of the Windows 10 firewall, and that you lot can use environmental variables in other versions, but we'd encourage you to just remove the variable and use the full and absolute file path to save yourself a headache today and downwards the road.

Finally, there'due south ane small just of import thing to proceed in mind here. For most applications, the main EXE file is the one you want to cake, but there are examples of applications where things are a bit counter-intuitive. Take Minecraft, for case. At outset glance it seems like y'all should blockMinecraft.exe , butMinecraft.exe is really  just the launcher file and the actual network connectivity happens through Java. And then, if you lot desire to restrict your child from connecting to online Minecraft servers you need to blockJavaw.exe and notMinecraft.exe . That's atypical, though, as well-nigh applications can exist blocked through the chief executable.

At any charge per unit, once you've selected your application and confirmed the path, you can finally click that "Adjacent" push button. On the "Action" screen of the sorcerer, select the "Block the connection" option, and then click "Next."

On the "Profile" screen, you're asked to select when the rule applies. Here, you have iii options:

  • Domain: The rule applies when a computer is connected to a domain.
  • Individual: The dominion applies when a computer is connected to a individual network, such as your dwelling house or minor concern network.
  • Public: The rule applies when a computer is connected to a public network, such as at a java shop or hotel.

RELATED: What'south the Departure Between Private and Public Networks in Windows?

So, for example, if you lot have a laptop that y'all use at home (a network you've defined as private) and at a coffee store (a network you've defined as public) and you want the dominion to apply to both places, you need to check both options. If you want the rule only to utilise when you lot're at the public Wi-Fi spot at the coffee shop, then just check Public. When in uncertainty, just check them all to block the awarding across all networks. When you've made your option click "Side by side".

The concluding step is to proper name your dominion. Give information technology a articulate name you'll recognize afterwards on. Nosotros named ours, simply, "Maxathon Block" to betoken which application we're blocking. If y'all want, you can add together a fuller clarification. When you've filled the appropriate information in, click the "Finish" button.

Yous'll now have an entry at the top of the "Outbound Rules" list for your new dominion. If your goal was blanket blocking y'all're all done. If you desire to tweak and refine the rule you can double click on the entry and make adjustments—like adding local exceptions (east.g. the application can't admission the Internet but information technology can connect so some other PC on your network and then you can apply a network resource or the like).

At this point we've achieved the goal outlined in the title of this article: all outbound communication from the awarding in question is now cut off. If you desire to farther tighten the grip you take on the application you lot can select the "Inbound Rules" option in right hand navigation panel of the "Windows Firewall with Advanced Security" and repeat the process, step for step, recreating an identical firewall rule that governs inbound traffic for that awarding too.

Testing the Rule

Now that the rule is active it's time to burn down upward the application in question and test it. Our examination awarding was the Maxthon web browser. Practically speaking, and for obvious reasons, information technology's not super useful to cake your spider web browser from accessing the Net. But, it does serve as a useful example, because nosotros can immediately and clearly demonstrate that the firewall rule is in result.


