# NetSh | blockinbound,allowoutbound | work on local not on remote

**URL:** <https://forums.powershell.org/t/netsh-blockinbound-allowoutbound-work-on-local-not-on-remote/12383>\
**Category:** PowerShell Help\
**Created:** [April 11, 2019, 10:19am UTC](https://forums.powershell.org/t/netsh-blockinbound-allowoutbound-work-on-local-not-on-remote/12383 "2019-04-11T10:19:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ustyne](https://avatars.discourse-cdn.com/v4/letter/u/47e85d/32.png) [@ustyne](https://forums.powershell.org/u/ustyne)\
**Post date:** [April 11, 2019, 10:19am UTC](https://forums.powershell.org/t/netsh-blockinbound-allowoutbound-work-on-local-not-on-remote/12383/1 "2019-04-11T10:19:31Z")

</div>

I have a mixed environment of 2008 /R2 and 2012 /R2

I am need to block blockinbound (default) traffic and allow all outbound traffic. I have written this if-else statement the evaluated the PowerShell version to determine either to run a NetSecurity cmdlet or a NetSh advfirewall.

The issue am having is with the netsh command. I works on local computer but will not on remote. Has anyone ran into this or is there a solution or am I doing something wrong?

Below is my process block with my - else code wrapped on a sriptblock

[pre]

PROCESS {  
Invoke-Command -Session $Servers -ScriptBlock {  
if ($PSVersionTable.PSVersion.Major -gt 3){  
Set-NetFirewallProfile `  
-DefaultInboundAction Block `  
-DefaultOutboundAction Allow  
}#if  
else{  
netsh advfirewall set allprofiles firewallpolicy blockinbound,allowoutbound  
}#else

if($PSVersionTable.PSVersion.Major -gt 3){  
Get-NetFirewallProfile -all | Select-Object Enabled,Name,LogAllowed,LogIgnored,LogFileName  
}#if  
else{  
#Show rule status  
netsh advfirewall show allprofiles  
}#else

}#Invoke  
}#PROCESS

[/pre]

&nbsp;

---

<div class="post-metadata">

**Author:** ![kvprasoon](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/kvprasoon/32/4449_2.png) [@kvprasoon](https://forums.powershell.org/u/kvprasoon)\
**Post date:** [April 11, 2019, 10:47am UTC](https://forums.powershell.org/t/netsh-blockinbound-allowoutbound-work-on-local-not-on-remote/12383/2 "2019-04-11T10:47:08Z")

</div>

When you say not working, are you getting any error or it just executes and do nothing ?

---

<div class="post-metadata">

**Author:** ![ustyne](https://avatars.discourse-cdn.com/v4/letter/u/47e85d/32.png) [@ustyne](https://forums.powershell.org/u/ustyne)\
**Post date:** [April 11, 2019, 1:00pm UTC](https://forums.powershell.org/t/netsh-blockinbound-allowoutbound-work-on-local-not-on-remote/12383/3 "2019-04-11T13:00:17Z")

</div>

It returns that the command was incorrect but the same command works on local firewall.

---

<div class="post-metadata">

**Author:** ![ustyne](https://avatars.discourse-cdn.com/v4/letter/u/47e85d/32.png) [@ustyne](https://forums.powershell.org/u/ustyne)\
**Post date:** [April 16, 2019, 8:35am UTC](https://forums.powershell.org/t/netsh-blockinbound-allowoutbound-work-on-local-not-on-remote/12383/4 "2019-04-16T08:35:44Z")

</div>

After much I have found the solution to my problem.

The NetSh help file content shows this command as an example

[pre]netsh advfirewall set allprofiles firewallpolicy blockinbound,allowoutbound[/pre]

It dose not work on a PSSession in a remote computer.

This is what worked on a remote computer.

[pre]netsh advfirewall set allprofiles firewallpolicy “blockinbound,allowoutbound”[/pre]

The blockinbound and allowinbound has to be in an open and closing quotation mark

**“blockinbound,allowoutbound”**

---

<div class="post-metadata">

**Author:** ![postanote](https://avatars.discourse-cdn.com/v4/letter/p/ebca7d/32.png) [@postanote](https://forums.powershell.org/u/postanote)\
**Post date:** [April 17, 2019, 12:01am UTC](https://forums.powershell.org/t/netsh-blockinbound-allowoutbound-work-on-local-not-on-remote/12383/5 "2019-04-17T00:01:50Z")

</div>

Good that you worked it all out, but as a rule passing multiples to certain commands, require proper quoting for success.

> **[about Quoting Rules - PowerShell](https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_quoting_rules?view=powershell-7.2)**
>
> Describes rules for using single and double quotation marks in PowerShell.

[https://trevorsullivan.net/2016/07/20/powershell-quoting](https://trevorsullivan.net/2016/07/20/powershell-quoting)

**Running external commands, always require special consideration.**

 

_> **[TechNet Wiki](https://social.technet.microsoft.com/wiki/contents/articles/7703.powershell-running-executables.aspx)**
>
> Technical articles, content and resources for IT Professionals working in Microsoft technologies_

 

_> **[Solve Problems with External Command Lines in PowerShell](https://devblogs.microsoft.com/scripting/solve-problems-with-external-command-lines-in-powershell/)**
>
> Summary: Microsoft Scripting Guy Ed Wilson discusses problems creating external command arguments using Windows PowerShell.   Hey, Scripting Guy! I am using an external program that takes a –o command-line parameter followed by a path location...._

 

_> **[Top 5 tips for running external commands in Powershell](https://powershelleverydayfaq.blogspot.com/2012/04/top-5-tips-for-running-external.html)**
>
> Running an external command in powershell looks pretty easy, to run notepad just do : notepad.exe Things get a little be more complicate..._

 

_> **[Using Windows PowerShell to run old command line tools (and their weirdest...](https://docs.microsoft.com/en-us/archive/blogs/josebda/using-windows-powershell-to-run-old-command-line-tools-and-their-weirdest-parameters)**_

 

_> **[Solve Problems with External Command Lines in PowerShell](https://devblogs.microsoft.com/scripting/solve-problems-with-external-command-lines-in-powershell/)**
>
> Summary: Microsoft Scripting Guy Ed Wilson discusses problems creating external command arguments using Windows PowerShell.   Hey, Scripting Guy! I am using an external program that takes a –o command-line parameter followed by a path location...._

 

_ **Why are you not using the built-in firewall cmdlets vs netsh?** _

```
CommandType Name Version Source                          
----------- ---- ------- ------                          
...         
Function Copy-NetFirewallRule 2.0.0.0 NetSecurity                     
Function Disable-NetFirewallRule 2.0.0.0 NetSecurity                     
Function Enable-NetFirewallRule 2.0.0.0 NetSecurity                     
Function Get-NetFirewallAddressFilter 2.0.0.0 NetSecurity                     
Function Get-NetFirewallApplicationFilter 2.0.0.0 NetSecurity                     
Function Get-NetFirewallInterfaceFilter 2.0.0.0 NetSecurity                     
Function Get-NetFirewallInterfaceTypeFilter 2.0.0.0 NetSecurity                     
Function Get-NetFirewallPortFilter 2.0.0.0 NetSecurity                     
...
Function Get-NetFirewallProfile 2.0.0.0 NetSecurity                     
Function Get-NetFirewallRule 2.0.0.0 NetSecurity                     
...
Function Get-NetFirewallSecurityFilter 2.0.0.0 NetSecurity                     
Function Get-NetFirewallServiceFilter 2.0.0.0 NetSecurity                     
Function Get-NetFirewallSetting 2.0.0.0 NetSecurity                     
Function New-NetFirewallRule 2.0.0.0 NetSecurity                     
Function Remove-NetFirewallRule 2.0.0.0 NetSecurity                     
Function Rename-NetFirewallRule 2.0.0.0 NetSecurity                     
Function Set-NetFirewallAddressFilter 2.0.0.0 NetSecurity                     
Function Set-NetFirewallApplicationFilter 2.0.0.0 NetSecurity                     
Function Set-NetFirewallInterfaceFilter 2.0.0.0 NetSecurity                     
Function Set-NetFirewallInterfaceTypeFilter 2.0.0.0 NetSecurity                     
Function Set-NetFirewallPortFilter 2.0.0.0 NetSecurity                     
...
Function Set-NetFirewallProfile 2.0.0.0 NetSecurity                     
Function Set-NetFirewallRule 2.0.0.0 NetSecurity                     
...
Function Set-NetFirewallSecurityFilter 2.0.0.0 NetSecurity                     
Function Set-NetFirewallServiceFilter 2.0.0.0 NetSecurity                     
Function Set-NetFirewallSetting 2.0.0.0 NetSecurity                     
Function Show-NetFirewallRule 2.0.0.0 NetSecurity                     
...

# Get parameters, examples, full and Online help for a cmdlet or function

# get function / cmdlet details
(Get-Command -Name Get-NetFirewallProfile).Parameters
Get-help -Name Get-NetFirewallProfile -Examples
Get-help -Name Get-NetFirewallProfile -Full
Get-help -Name Get-NetFirewallProfile -Online

# Get parameter that accepts pipeline input
Get-Help Get-NetFirewallProfile -Parameter * | 
Where-Object {$_.pipelineInput -match 'true'} | 
Select * 

# List of all parameters that a given cmdlet supports along with a short description:
Get-Help Get-NetFirewallProfile -para * | 
Format-Table Name, { $_.Description[0].Text } -wrap

Get-Help about_*
Get-Help about_Functions
```

---

<div class="post-metadata">

**Author:** ![dotnVo](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@dotnVo](https://forums.powershell.org/u/dotnVo)\
**Post date:** [May 16, 2024, 8:32pm UTC](https://forums.powershell.org/t/netsh-blockinbound-allowoutbound-work-on-local-not-on-remote/12383/6 "2024-05-16T20:32:58Z")

</div>


