Remarks: -Sets a new parameter value on an identified rule. The command fails if the rule does not exist. To create a rule, ...


Remarks:

      -Sets a new parameter value on an identified rule. The command fails
       if the rule does not exist. To create a rule, use the add command.
      -Values after the new keyword are updated in the rule.  If there are
       no values, or keyword new is missing, no changes are made.
      -If multiple rules match the criteria, all matching rules will
       be updated.
      -Rule name should be unique and cannot be "all".
      -Auth1 can be comma-separated lists of options.
       Computerpsk and computerntlm methods cannot
       be specified together for auth1.
      -The use of DES, MD5 and DHGroup1 is not recommended.
       These cryptographic algorithms are provided for backward
       compatibility   only.
      -The minimum main mode keylifetime is mmkeylifetime=1min.
       The maximum main mode mmkeylifetime= 2880min.
       The minimum number of sessions= 0 sessions.
       The maximum = 2,147,483,647 sessions.
      -The mmsecmethods keyword default sets the policy to:
       dhgroup2-aes128-sha1,dhgroup2-3des-sha1
      -Certhash specifies the thumbprint, or hash of the certificate.
      -Followrenewal specifies whether to automatically follow renewal
       links in certificates. Only applicable for certificate section
       (requires certhash).
      -Certeku specifies the comma separated list of EKU OIDs to match
       in the certificate.
      -Certname specifies the string to match for certificate name
       (requires certnametype).
      -Certnametype specifies the certificate field for the certname
       to be matched against (requires certname).
      -Certcriteriatype specifies whether to take the action with the
       certificate when selecting the local certificate, validating
       the peer certificate, or both.

Examples:

      Change the mmescmethods, description
      and keylifetime of a rule named test

      Netsh advfirewall mainmode set rule name="test" 
      new description="Mainmode for RATH2"
      Mmsecmethods=dhgroup2:3des-sha256,ecdhp384:3des-sha384
      auth1=computerntlm  mmkeylifetime=2min profile=domain