You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Windows Server 2016外部NIC仅允许出站更新流量?

Configure Windows Server 2016 External NIC for Restricted Critical Outbound Traffic

Hey there, let's walk through how to set up your external NIC (WAN-IP2) to only allow essential outbound traffic like Windows Updates, while keeping it locked down. Since you want to bypass the bandwidth-limited pfSense for this, we'll focus on native Windows tools to get this done right.

Step 1: Re-enable & Configure the External NIC

First, we need to bring the NIC back online with the correct network settings:

  • Open Network and Sharing Center, find your disabled external NIC, right-click it and select Enable.
  • Right-click the NIC again, choose Properties, then double-click Internet Protocol Version 4 (TCP/IPv4).
    • Set a static IP: WAN-IP2 (your assigned public IP)
    • Subnet mask: Use the value provided by your service provider (usually 255.255.255.0 for most VPS setups)
    • Default gateway: Enter the public gateway from your provider do NOT use pfSense's 192.168.100.1—this ensures traffic from this NIC routes directly out the WAN, not through your internal network.
    • DNS servers: Use public options like 8.8.8.8/1.1.1.1 or your provider's DNS to ensure update servers resolve correctly.
  • Optional but recommended: Uncheck Internet Protocol Version 6 (TCP/IPv6) to reduce unnecessary attack surface.

Step 2: Lock Down Windows Firewall for the External NIC

The core of this setup is using Windows Defender Firewall's advanced rules to block all outbound traffic by default, then explicitly allow only critical services.

2.1 Create an Allow Rule for Critical Traffic

  1. Open Windows Defender Firewall > click Advanced Settings on the left.
  2. Select Outbound Rules from the left pane, then click New Rule on the right.
  3. Choose Custom as the rule type, click Next.
  4. Program tab:
    • For Windows Updates: Select This program path and browse to C:\Windows\System32\wuauclt.exe (the Windows Update client) OR C:\Windows\System32\svchost.exe (note: if using svchost, you'll need to specify the wuauserv service in the next step under Services).
    • If you need other critical services (like NTP for time sync), repeat this rule creation process for their respective executables.
  5. Protocol and Ports tab:
    • For Windows Updates, you'll need TCP ports 80 (HTTP) and 443 (HTTPS). For NTP time sync, add UDP port 123.
    • Select Specific remote ports and enter 80,443,123 (adjust based on your needs), click Next.
  6. Scope tab:
    • Local IP address: Choose These IP addresses and add WAN-IP2—this ensures the rule only applies to your external NIC.
    • Remote IP address: You can either add known Microsoft update server IP ranges (for strict security) or select Any IP address (simpler, since Microsoft's update IPs change frequently; the port restriction still keeps it secure).
  7. Action tab: Select Allow the connection, click Next.
  8. Profile tab: Uncheck Domain and Private, only check Public (since this is a WAN-facing NIC), click Next.
  9. Name the rule something like Allow Critical Outbound (WAN NIC) and click Finish.

2.2 Set Default Deny for the External NIC

To ensure all unapproved traffic is blocked:

  • In Outbound Rules, find the default All Outbound Connections rule (which allows everything). Right-click it > Properties.
  • Go to the Advanced tab, uncheck your external NIC from the Interfaces list. This removes the default allow behavior for this specific NIC.
  • For extra strictness: Create a new custom outbound rule that blocks all traffic on the external NIC. Set it to apply to All programs, Any protocol, local IP WAN-IP2, remote IP Any, action Block the connection, profile Public. Name it Deny All Outbound (WAN NIC) and make sure this rule is placed below your allow rules (use the Move Up/Down buttons to adjust priority).

Step 3: Verify the Configuration

Test to make sure everything works as expected:

  • Open Command Prompt and run tracert windowsupdate.microsoft.com—you should see traffic routing through your provider's WAN gateway, not pfSense.
  • Initiate a Windows Update check—this should complete successfully.
  • Try pinging a random public IP or accessing a non-update website via a browser (using the external NIC, you might need to force the browser to use this adapter if you have multiple NICs) — this should fail, confirming the block is working.

Extra Security Tips

  • Keep Windows Defender Firewall's Public profile enabled at all times for this NIC.
  • Periodically review your outbound rules to remove any outdated or unnecessary allowances.
  • If you need to add other critical services (like certificate revocation checks), repeat the rule creation process for their required ports/programs.

内容的提问来源于stack exchange,提问作者MKZ

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:16:17