s! type = FILEANDPRINT|REMOTEADMIN|REMOTEDESKTOP|UPNP|ALL mode = ENABLE|DISABLE scope = ALL|SUBNET|CUSTOM addresses = addresses ...

%1!s!
      [ type = ] FILEANDPRINT|REMOTEADMIN|REMOTEDESKTOP|UPNP|ALL
      [ [ mode = ] ENABLE|DISABLE
        [ scope = ] ALL|SUBNET|CUSTOM
        [ addresses = ] addresses
        [ profile = ] CURRENT|DOMAIN|STANDARD|ALL ]

  Sets firewall service configuration.

  Parameters:

  type - Service type.
      FILEANDPRINT  - File and printer sharing.
      REMOTEADMIN   - Remote administration.
      REMOTEDESKTOP - Remote assistance and remote desktop.
      UPNP          - UPnP framework.
      ALL           - All types.

  mode - Service mode (optional).
      ENABLE  - Allow through firewall (default).
      DISABLE - Do not allow through firewall.

  scope - Service scope (optional).
      ALL    - Allow all traffic through firewall.
      SUBNET - Allow only local network (subnet) traffic through firewall.
      CUSTOM - Allow only specified traffic through firewall.

  addresses - Custom scope addresses (optional).
              This comma-separated scope can contain IPv4 addresses,
              IPv6 addresses, subnets, ranges, or the keyword LocalSubnet.

  profile - Configuration profile (optional).
      CURRENT  - Applies to the active profile.  Active profile can be domain,
                 standard (i.e. private), or public. (default).
      DOMAIN   - Applies to the domain profile.
      STANDARD - Applies to the standard (i.e. private) profile.
      ALL      - Applies to the domain and standard (i.e. private) profile.
                 Does not apply to the public profile.

  Remarks: 'scope' must be 'CUSTOM' to specify 'addresses'.
           ‘addresses' can not contain Unspecified or Loopback addresses.

  Examples:

      %1!s! FILEANDPRINT
      %1!s! REMOTEADMIN DISABLE
      %1!s! REMOTEDESKTOP ENABLE CUSTOM
          157.60.0.1,172.16.0.0/16,10.0.0.0/255.0.0.0,
          12AB:0000:0000:CD30::/60,LocalSubnet
      %1!s! type=UPNP
      %1!s! type=REMOTEADMIN mode=ENABLE scope=SUBNET
      %1!s! type=REMOTEDESKTOP mode=ENABLE scope=CUSTOM
          addresses=157.60.0.1,172.16.0.0/16,10.0.0.0/255.0.0.0,
          12AB:0000:0000:CD30::/60,LocalSubnet

      IMPORTANT: "netsh firewall" is deprecated;
      use "netsh advfirewall firewall" instead.
      For more information on using "netsh advfirewall firewall" commands
      instead of "netsh firewall", see KB article 947709
      at http://go.microsoft.com/fwlink/?linkid=121488 .