Event ID 4953

Windows Firewall ignored a rule because it could not be parsed

Windows Firewall ignored a rule because it could not be parsed.

Profile:              %1

Reason for Rejection: %2

Rule:
    ID:   %3
    Name: %4


This event generates if Windows Firewall was not able to parse Windows Firewall rule for some reason.

It can happen if a Windows Firewall rule registry entry was corrupted, or from misconfigured Group Policy settings.

Auditing:     Always

Usually indicates a configuration issue, not a security issue.


Volume:     Low


Microsoft Documentation

Event ID - 4953



NameFieldInsertion StringOSExample
ProfileProfile%1Any All
Reason for RejectionReasonForRejection%2Any An error occurred.
IDRuleId%3Any SearchProtocolHost-2
NameRuleName%4Any -


Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"MPSSVC Rule-Level Policy Change"



LEFT/RIGHT arrow keys for navigation

Back to List