Listener & firewall hardening
Port Audit Checklist Generator
Generate an ordered listener and firewall audit checklist for your Windows home server: TCP listener inventory, binding scope triage, rule review, exposure hardening and before/after validation.
Audit a Windows home server's listeners and firewall before something else does
A Windows home server listens on more ports than the one service you installed for it. This generator builds an ordered audit checklist from your exposure plan and container setup: dump every TCP listener, triage by binding scope, review the enabled inbound allow rules, harden the exposure path, and finish with a before/after diff so you know exactly what your changes did. Every command it produces is built-in PowerShell — no third-party tools.
The checklist is derived from a real audit: on our Beelink EQi12 (Windows 11 + Docker Desktop + Jellyfin), a full listener dump found 25 unique TCP ports across 36 bindings and 169 enabled inbound allow rules, with temporary firewall rules at zero before and after the session. The complete measured tables live in the full port audit report.
Triage by binding scope, not by port number
The single most useful lesson from a listener audit: binding scope determines exposure. A socket on 127.0.0.1 or ::1 is unreachable from the network no matter what process owns it. The same port bound to 0.0.0.0 or :: is reachable from your whole LAN — and if a router port-forward exists, from the internet. On our audit machine, SMB's port 445 was bound only to :: while the legacy NetBIOS port 139 sat on four specific interfaces including Docker bridges — a difference you will only see in a listener dump, never in a browser tab.
The reference numbers this checklist is calibrated against
| Reference point | Measured value | Source file (measurement repo) |
|---|---|---|
| Unique TCP ports listening | 25 | EQi12_Security_02_TCP_LISTENERS.csv |
| Total listener bindings (port × interface) | 36 | same file |
| Enabled inbound allow rules | 169 | EQi12_Security_06_ENABLED_INBOUND_ALLOW.csv |
| Temporary firewall rules (before / after) | 0 / 0 | EQi12_Security_07/08 CSVs |
| Jellyfin listener scope | 0.0.0.0:8096 (Docker publish default) | EQi12_Security_02_TCP_LISTENERS.csv |
Your counts will differ where your installed software differs — the method and the category breakdown are the transferable parts.
Commands each checklist step relies on
Get-NetTCPConnection -State Listen |
Select-Object LocalAddress, LocalPort, OwningProcess |
Sort-Object LocalPort
Get-Process -Id (Get-NetTCPConnection -State Listen).OwningProcess -ErrorAction SilentlyContinue |
Select-Object Id, ProcessName | Sort-Object Id -Unique
Get-NetFirewallRule -Enabled True -Direction Inbound -Action Allow |
Select-Object DisplayName, Profile | Sort-Object DisplayNameThe rule families that matter on a headless box
Our 169 rules grouped into a handful of families, and most of the risk sat in three of them: the File and Printer Sharing family on the Public profile (the one real misconfiguration we found — SMB accepting inbound on an untrusted network), the Cast to Device family partially enabled on Public, and the pile of consumer-app rules (Teams, game launchers, Solitaire) that serve zero purpose on a headless server. The Core Networking family should be left alone — breaking DHCP or ICMPv6 rules fails in confusing ways for near-zero gain. The full grouped tables are in the audit report.
Frequently asked questions
How do I audit which ports my Windows home server is listening on?
Run Get-NetTCPConnection -State Listen elevated and map PIDs with Get-Process -Id. Our Windows 11 + Docker Desktop machine showed 25 ports across 36 bindings — including services we never deliberately exposed.
Which listening ports should I worry about?
Only sockets bound to 0.0.0.0, :: or a LAN address are reachable. Loopback bindings are effectively safe. Triage by binding scope, not port number.
How many firewall rules is normal?
Our box had 169 enabled inbound allow rules, most added silently. The count is not the problem — unreviewed rules are. Group by family, disable what a headless server does not need.
Should I port-forward services to the internet?
Prefer a VPN into the home network. Forgotten port-forwards are the most common compromise path, and your listener inventory is exactly what they expose.