Forum Discussion

Deleted's avatar
Deleted
Sep 27, 2023

BUG: Firewall rule spam when RDSH role is enabled, slow perf. / start / taskbar unresponsive

Dear Microsoft Team,
could we assure that this issue is fixed in Windows Server vNext and can be backported?

Issue description:
The issue is that on RDSH enabled Windows Server 2019, 2022 and likely vNext the Firewall rules duplicate for each user logon 

This is a range of inbound and outgoing rules for different services such

  • Narrator
  • Start
  • Captive Portal Flow
  • Your account
  • Windows Search
  • Windows Security
  • windows_ie_ac_001

etc. it is really a long list, not all rules are affected likely those tied to "apps"

an official workaround was documented https://support.microsoft.com/en-gb/help/4490481/windows-10-update-kb4490481 but I wonder why this could not be deployed at scale and why seems impossible to run a remediation script to detect uniquely duplicate Defender Firewall rules with an CU. This would be a breeze!

Issues:
- high cpu load

- taskbar does not work or become unresponsive

- start does not work or become unresponsive

- much slower logon times

How to reproduce: 
deploy Windows Server 2019 / 2022 with RDSH role
logon / logoff different user domain accounts

check Defender Firewall rules growing

Priority: high

external reference:
https://community.spiceworks.com/topic/2285411-server2019-rds-hundreds-of-firewall-rules-per-user-per-session
https://www.reddit.com/r/sysadmin/comments/un1i2z/windows_rds_server_2022_taskbar_and_start/

Thank you so much for considering this!

4 Replies

  • But hey, paint can do layers now. That is more important than any server OS bug.
    • Deleted's avatar
      Deleted
      and remove background thanks to AI. Piracy of Adobe Photoshop looses the use case 🙂 #joking
      then thankfully the MSpaint change is not related to the WS PG.
  • backport of the fix to WS 2019 & 2022 is much appreciated.
    • FredrikKGustafsson's avatar
      FredrikKGustafsson
      Copper Contributor

      Been around way to long. Time to actually fix this...

       

      https://social.technet.microsoft.com/Forums/en-US/992e86c8-2bee-4951-9461-e3d7710288e9/windows-servr-2016-rdsh-firewall-rules-created-at-every-login?forum=winserverTS#992e86c8-2bee-4951-9461-e3d7710288e9

Resources