Windows Filtering Platform - WFP blocking packets (dropping)

Currently using Windows 2012 RDSH to present apps to the users.   I had an interesting event yesterday where users reported sluggishness on an app from one of the RDS servers and saw these entries in the audit logs.

The Windows Filtering Platform has blocked a packet.

Application Information:

Process ID: 0

Application Name: -

Network Information:

Direction: Bidirectional

Source Address:

Source Port: 49155

Destination Address:

Destination Port: 58564

Protocol: 17

Filter Information:

Filter Run-Time ID: 70905

Layer Name: Datagram Data

Considering that protocol 17 is UDP and their using PCoIP it's pretty safe to say that it may have been windows firewall causing grief for the end users and their experience.   I looked at the firewall and the firewall profiles for the domain was off while private and public were on.  

has anyone encountered this previously?   Windows blocking/dropping UDP packets because of filtering but not all the time just sometimes? 


0 Kudos
1 Reply

There may be a filter applied that is blocking the traffic.

run:  netsh wfp show filters

Open up the file it generated "filters.xml"

Search for that filter run-time ID in xml file to see what is blocking it.

0 Kudos