WFAS
Built into Windows 7 onward, including Windows Server equivalents, WFAS is the host firewall that can be used to control network traffic. WFAS is stateful, without being dependent on MDAV’s active mode, and comes preloaded with rules to protect systems out of the box, though it can also be managed centrally with the usual administrator tools for additional control and customization.
A key part of WFAS to understand is the concept of profiles, which are containers for rules depending on the connection determined by Network Location Awareness (NLA) (the NlaSvc
service). There are three profiles, corresponding to NLA’s three location types:
- Public, which is the most restrictive, and for areas such as public Wi-Fi, but also the default network
- Private, which is behind a NAT and, most commonly now, the end user’s home or non-Active Directory Domain Services network
- Domain, which is an on-premises Active Directory Domain Services network, determined...