TechOps Workbench
SQL SERVER · WINDOWS INBOUND FIREWALL RULES

Open the intended path.
Keep the scope explicit.

Generate reviewable PowerShell rules for the addresses and ports your deployment actually uses.

Network profile

01 / INPUTS
Only for clients needing instance discovery. A known TCP port avoids this dependency.
◇ Generates commands only. No firewall changes applied.

Inbound rule plan

02 / RESULTS
REVIEW ON THE TARGET HOST · ELEVATED POWERSHELL REQUIRED

Scoped rules to create

—RULES
PurposeProtocol / portRemote scope

Create rules · changes firewall if executed

Review addresses, profiles and existing policy before running on the SQL host. These are inbound local-host rules; the script does not configure SQL ports or restart services.

Connectivity test · run from an authorized client

Tests TCP reachability only, not SQL login, TLS or UDP Browser discovery. This website does not perform the test.

UNDERSTAND THE SCOPE

Ports follow services.
Rules follow clients.

Confirm listening ports and authorized source addresses before applying the generated plan.

Engine, listener and endpoint

The engine and AG listener ports accept application connections. AG replication uses a separately configured database-mirroring endpoint; allow that port between the replica hosts. Browser discovery uses UDP 1434 and does not replace opening the engine’s actual TCP port.

Static ports and profiles

This tool assumes known, fixed listening ports. Named instances can use dynamic ports; configure a fixed port and restart the instance as required before relying on a fixed-port rule. Select the Windows network profiles actually active on the host.

What is not configured

Rules are IPv4-only and remote-scoped; every local interface is covered on the chosen port and profile. Upstream firewalls, cloud NSGs, load balancers, NAT, WSFC, DNS, outbound restrictions and domain policy need separate review. Port-based rules do not bind access to the SQL executable.

The script stops if a generated rule name already exists rather than replacing existing policy. Existing broader rules or explicit block rules can affect the effective result. Applying this plan does not prove the server is secure or reachable.

Guidance checked October 5, 2026. Public profile and unrestricted remote scopes are outside this builder’s supported inputs.