You may have experienced VPN block issues by Windows firewall, usually it’s a default setting, but there’s always a way to get around it and get connected again. You may refer to the solutions below to proceed with.
Add Exclusion
Open Windows Defender Security Center
Go to Virus & Threat protection settings
Select Exclusions
Select Add or remove exclusions
Select Add an exclusion and add your VPN client software
Change allow app settings
Open Control Panel.
Select System and Security
Click Windows Defender Firewall
On the left pane, click Allow an app or a feature through Windows Firewall. A window in which you can allow or prevent any app will display
Click change Settings
Check for your VPN from the list of programs and apps you want to allow through your firewall
Check Public or Private to select the network type on which you want the VPN to run
If you cannot find your VPN, click Allow another app
Select your VPN and then click Add, then click OK.
Change adapter settings
Open Control Panel and select Network & Internet.
Select Network and Sharing Center.
On the left pane, click Change adapter settings.
Click File
Select New incoming connection
Select all users you want to access your VPN connection
Check Through the Internet
Click Next
From the list of protocols, mark the Internet protocols you want your VPN to connect to
Double click Internet Protocol Version 4 (TCP/IPv4)
Go to Control Panel again and select Windows Defender Firewall
Click Advanced Settings.
Click Inbound Rules > Actions.
Click New Rule...
In the Wizard, choose Port and click Next. Most VPN clients use ports 500 and 4500 UDP, and port 1723 for TCP. You can use TCP and insert 1723 in Specific remote ports field
Click Next
Select Allow the connection and click Next
When asked ‘When does this rule apply?’ select all options (Domain, Private, Public) and apply the rule to all
Choose a name and description to fill the Name and Description
Click Finish
Create new inbound rule
Open Windows firewall with advanced security
Click inbound rules on the left
Click New rule on the right
Click Custom rule
Specify programs or leave as all programs
Specify ports or leave as all ports
Click These IP addresses under remote IP
Click This IP address range
Type From 10.8.0.1 To 10.8.0.254
Close and click Next, then leave as Allow the connection
Apply to all profiles
Name your profile and click Finish
You should then be able to connect to your home devices through VPN
Enable rule for PPTP
Open Control Panel
Select Windows Firewall
Select Advanced Settings
Search for the ‘Routing and Remote Access‘ under Inbound Rules and Outbound Rules. For Inbound Rules: right-click Routing and Remote Access (PPTP-In), select Enable Rule. For Outbound Rules: right-click Routing and Remote Access (PPTP-Out), select Enable Rule.
Open ports
In order to allow your VPN traffic to pass through the firewall, open the following ports:
IP Protocol=TCP, TCP Port number=1723 – used by PPTP control path
IP Protocol=GRE (value 47) – used by PPTP data path
Make sure that these ports are allowed on Windows Firewall with corresponding network profile.
DO NOT configure RRAS static filters if you are running on the same server RRAS based NAT router functionality. This is because RRAS static filters are stateless and NAT translation requires a stateful edge firewall like ISA firewall.
In general, VPN error 807 indicates that the network connection between your computer and the VPN server was interrupted. This also can be caused by a problem in the VPN transmission and is commonly the result of internet latency or simply that your VPN server has reached capacity. Try to reconnect to the VPN server.
Turn off SSL monitoring
Depending on your firewall or security software, there are steps to take to fix VPN blocked by Windows firewall. Here’s what to do if you’re using NOD32 or Kaspersky:
NOD32:
Select Setup
Select Advanced Setup
Select Antivirus and antispyware
Select Web access protection
Select HTTP, HTTPS > HTTP scanner setup, and set HTTPS filtering mode to Do not use HTTPS protocol checking.
Kaspersky:
Select Settings
Select Traffic Monitoring panel
Select Port Settings or settings
Select Network
Select Port Settings and uncheck the box for port 443/SSL