Event ID: 4953
Windows Firewall ignored a rule because it could not be parsedWindows Firewall ignored a rule because it could not be parsed. Profile: %1 Reason for Rejection: %2 Rule: ID: %3 Name: %4
This event generates if Windows Firewall was not able to parse Windows Firewall rule for some reason.
It can happen if a Windows Firewall rule registry entry was corrupted, or from misconfigured Group Policy settings.
Auditing:
Always
Usually indicates a configuration issue, not a security issue.
Volume:
Low
Microsoft Documentation
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"MPSSVC Rule-Level Policy Change"
Operating Systems:
Windows Vista Windows 2008 Windows 2008 R2 Windows 7 Windows 2012 Windows 2012 R2 Windows 8 Windows 8.1 Windows 10 Windows 2016 Windows 2019Tags:
Audit FailureLEFT/RIGHT arrow keys for navigation
Back to List