Event ID: 4957

Windows Firewall did not apply the following rule

Rule Information:
    ID:   %1
    Name: %2

Error Information:
    Reason: %3 resolved to an empty set.

This event generates when Windows Firewall starts or apply new rule, and the rule cannot be applied for some reason.

It can happen if a Windows Firewall rule registry entry was corrupted, or from misconfigured Group Policy settings.

Auditing:     Always

Usually indicates a configuration issue, not a security issue.

Volume:     Low

Name Field Insertion String OS Example
ID RuleId %1 Any CoreNet-Teredo-In
Name RuleName %2 Any Core Networking - Teredo (UDP-In)
Reason RuleAttr %3 Any Local Port

Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"MPSSVC Rule-Level Policy Change"

