You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何给Windows防火墙拦截的应用添加启动弹窗提醒?

解决Windows防火墙拦截应用时的通知提醒问题

一、现成工具推荐

  • GlassWire:你提到的工具本身就支持应用网络拦截的实时通知,它能监控所有应用的网络活动,当被防火墙拦截的应用尝试联网时,会弹出清晰提示框,还能直接在界面内快速调整防火墙规则,无需手动进入防火墙设置查找。
  • NetLimiter:同样具备应用网络监控与拦截通知功能,除了弹窗提醒,还能实时查看应用流量消耗情况,方便管控后台更新类的流量占用。

二、手动编写脚本实现

核心思路

通过监控Windows防火墙的拦截日志,当检测到Windows Store(或指定应用)被拦截的事件时,自动弹出自定义通知。

具体步骤

  1. 开启防火墙日志记录

    • 打开Windows Defender防火墙高级设置,右键点击「Windows Defender防火墙属性」,切换到「域/专用/公用」标签页,在「日志记录」区域点击「自定义」。
    • 设置日志文件路径(例如C:\Windows\System32\LogFiles\Firewall\pfirewall.log),勾选「记录被丢弃的数据包」,点击确定保存设置。
  2. 编写PowerShell监控脚本
    创建一个.ps1格式的脚本文件,内容如下:

    # 定义目标应用名称和防火墙日志路径
    $targetApp = "WinStore.App.exe"
    $firewallLogPath = "C:\Windows\System32\LogFiles\Firewall\pfirewall.log"
    
    # 实时监控日志文件新增内容
    Get-Content $firewallLogPath -Wait | ForEach-Object {
        # 匹配目标应用被拦截的日志记录
        if ($_ -match $targetApp -and $_ -match "DROP") {
            # 构造并弹出Toast通知
            $notificationTitle = "应用被防火墙拦截"
            $notificationText = "Windows Store已被Windows防火墙拦截,请解除防火墙规则以访问Windows Store"
            [Windows.UI.Notifications.ToastNotificationManager, Windows.UI.Notifications, ContentType = WindowsRuntime] > $null
            $template = [Windows.UI.Notifications.ToastNotificationManager]::GetTemplateContent([Windows.UI.Notifications.ToastTemplateType]::ToastText02)
            $textElements = $template.GetElementsByTagName("text")
            $textElements[0].AppendChild($template.CreateTextNode($notificationTitle)) > $null
            $textElements[1].AppendChild($template.CreateTextNode($notificationText)) > $null
            $toast = [Windows.UI.Notifications.ToastNotification]::new($template)
            [Windows.UI.Notifications.ToastNotificationManager]::CreateToastNotifier("FirewallBlockAlert").Show($toast)
            # 避免短时间内重复弹窗,暂停10秒
            Start-Sleep -Seconds 10
        }
    }
    
  3. 设置脚本开机自动运行

    • 按下Win + R,输入shell:startup打开系统启动文件夹。
    • 创建一个.bat批处理文件,内容如下:
      @echo off
      powershell -ExecutionPolicy Bypass -File "C:\你的脚本存放路径\FirewallAlert.ps1"
      
    • 将批处理文件放入启动文件夹,每次开机后脚本会自动后台运行,监控防火墙日志。

注意事项

  • 需确保PowerShell执行权限已调整为允许,可通过命令Set-ExecutionPolicy RemoteSigned进行设置(执行时需管理员权限)。
  • 防火墙日志会持续增长,定期清理可避免监控脚本卡顿。

内容的提问来源于stack exchange,提问作者Philosopher

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 12:59:56