How to disable stealth mode - Windows Server (2024)

  • Article

This article discusses how to disable stealth mode (a Windows filtering platform feature).

Original KB number: 2586744

Introduction

Windows Server or Windows client computers do not send Transmission Control Protocol (TCP) reset (RST) messages or Internet Control Message Protocol (ICMP) unreachable packets across a port that does not have a listening application.Several applications rely on the behavior that is described in RFC 793, "Reset Generation," Page 35f. These applications require the TCP RST packet or ICMP unreachable packet as a response if they knock on a port that has no listener. If they don't receive this response, the applications might not be able to run correctly on Windows.Typically, the effect of this dependency is that stealth mode may cause a 20-second delay for regular TCP applications to reconnect if the remote peer loses the connection state and that notification packet doesn't reach the client.One example of this behavior is Lotus Notes Client. The client can be configured to use different Lotus Notes servers. If the service is not running on the first configured server, the client switches immediately to the second server if it receives a TCP RESET command. If stealth mode is enabled, no TCP RESET is received by the client. The client then waits for the last SYN retransmit to time out before it tries the next server in the list.

Cause

For ports on which no application listens, the stealth mode feature blocks the outgoing ICMP unreachable packet and TCP RST messages.
Stealth mode also applies to the endpoints that are in a paused state because of an overrun in the listen backlog parameter.

Resolution

WarningStealth mode is an important security feature. Disabling it can make the computer vulnerable to attack, even in managed corporate domain networks and behind edge firewalls. Therefore, we strongly recommend that you keep stealth mode active, and disable it only if it is required.

Caution

Follow the steps in this section carefully. Serious problems might occur if you modify the registry incorrectly. Before you modify it, back up the registry for restoration in case problems occur.

Stealth mode is a core security feature. For any given configuration, stealth mode should stay enabled unless there is a strong, valid argument for disabling it.
Stealth mode can be disabled by using any of the following methods:

  • You can set the DisableStealthMode keyword in the Firewall configuration service provider CSP) by using Microsoft Intune or another Mobile Device Management system.
  • An Independent software vendor (ISV) can use the Windows Filtering Platform (WFP) API to replace the stealth filters with proprietary filters.
  • You can disable the firewall for all profiles. (We do NOT recommend this method.)
  • You can add a "disable" value to either of the following sets of registry subkeys: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\DomainProfile HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\PublicProfile HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\PrivateProfile HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\PublicProfile HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile

Note

In the Software hive "Policy" section, the StandardProfile entry is used only if a legacy firewall GPO still exists.

In either set of subkeys, add the following value:
Value: DisableStealthMode
Type: REG_DWORD
Data: 0x00000000 (default - StealthMode enabled) 0x00000001 (StealthMode disabled)

Caution

Stealth mode cannot be deactivated by disabling the firewall service (MpsSvc). This is an unsupported configuration. For more information, see the "Disable Windows Defender Firewall with Advanced Security" section of "Windows Defender Firewall with Advanced Security Administration with Windows PowerShell."

More information

Stealth Mode in Windows Firewall with Advanced Security
Disable Stealth Mode in the "[MS-GPFAS]: Group Policy: Firewall and Advanced Security Data Structure" specification
Appendix B: Product Behavior in "[MS-FASP]: Firewall and Advanced Security Protocol" specification (look for FW_PROFILE_CONFIG_DISABLE_STEALTH_MODE in this appendix)

Third-party information disclaimer

The third-party products that this article discusses are manufactured by companies that are independent of Microsoft. Microsoft makes no warranty, implied or otherwise, about the performance or reliability of these products.

How to disable stealth mode - Windows Server (2024)
Top Articles
Windows 10 Reset VS Clean Install VS Fresh Start, Detailed Guide! - MiniTool
Windows 10 System Restore, Refresh, Reset, Fresh Start & Reinstall guide
Northern Counties Soccer Association Nj
Pollen Count Los Altos
Repentance (2 Corinthians 7:10) – West Palm Beach church of Christ
Overnight Cleaner Jobs
Bellinghamcraigslist
Tx Rrc Drilling Permit Query
Wal-Mart 140 Supercenter Products
Steve Strange - From Punk To New Romantic
Whiskeytown Camera
Mndot Road Closures
Progressbook Brunswick
Fire Rescue 1 Login
What is a basic financial statement?
Buying risk?
Munich residents spend the most online for food
Mzinchaleft
Pizza Hut In Dinuba
Doublelist Paducah Ky
Sef2 Lewis Structure
Red8 Data Entry Job
480-467-2273
The Eight of Cups Tarot Card Meaning - The Ultimate Guide
When His Eyes Opened Chapter 3123
Encore Atlanta Cheer Competition
Duke University Transcript Request
Imagetrend Elite Delaware
How to Use Craigslist (with Pictures) - wikiHow
Kacey King Ranch
Siskiyou Co Craigslist
Newsday Brains Only
Netherforged Lavaproof Boots
Viewfinder Mangabuddy
20 Best Things to Do in Thousand Oaks, CA - Travel Lens
Tugboat Information
Pa Legion Baseball
Royals Yankees Score
Craigslist Com St Cloud Mn
Sound Of Freedom Showtimes Near Amc Mountainside 10
Senior Houses For Sale Near Me
Unit 11 Homework 3 Area Of Composite Figures
N33.Ultipro
Oakley Rae (Social Media Star) – Bio, Net Worth, Career, Age, Height, And More
Dancing Bear - House Party! ID ? Brunette in hardcore action
Benjamin Franklin - Printer, Junto, Experiments on Electricity
Workday Latech Edu
Used Sawmill For Sale - Craigslist Near Tennessee
Chitterlings (Chitlins)
Inside the Bestselling Medical Mystery 'Hidden Valley Road'
Lorcin 380 10 Round Clip
Latest Posts
Article information

Author: Chrissy Homenick

Last Updated:

Views: 5828

Rating: 4.3 / 5 (54 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Chrissy Homenick

Birthday: 2001-10-22

Address: 611 Kuhn Oval, Feltonbury, NY 02783-3818

Phone: +96619177651654

Job: Mining Representative

Hobby: amateur radio, Sculling, Knife making, Gardening, Watching movies, Gunsmithing, Video gaming

Introduction: My name is Chrissy Homenick, I am a tender, funny, determined, tender, glorious, fancy, enthusiastic person who loves writing and wants to share my knowledge and understanding with you.