# Adds the inbound Windows Firewall rule for igneumd.exe (started by ALLOW-FIREWALL.bat). Runs itself again elevated, # removes any block rule Windows made for the exe (the "Cancel" button on the prompt creates one), then adds an allow # rule for the exe on the private and domain profiles. 3 October 2026. param([switch]$Elevated) $root = Split-Path -Parent $MyInvocation.MyCommand.Path $exe = Join-Path $root 'igneumd.exe' $rule = 'Igneum node (igneumd)' if (-not $Elevated) { Write-Host "asking for administrator rights to add the firewall rule for $exe" $psArgs = @('-NoProfile', '-ExecutionPolicy', 'Bypass', '-File', ('"' + $PSCommandPath + '"'), '-Elevated') try { Start-Process -FilePath powershell.exe -Verb RunAs -Wait -ArgumentList $psArgs } catch { Write-Host "not elevated ($_); nothing changed"; exit 1 } Write-Host 'done. Start the node again with START-NODE.bat.' exit 0 } try { $blocked = @(Get-NetFirewallApplicationFilter -ErrorAction SilentlyContinue | Where-Object { $_.Program -and ($_.Program -ieq $exe) } | Get-NetFirewallRule | Where-Object { $_.Action -eq 'Block' }) foreach ($b in $blocked) { Write-Host "removing block rule '$($b.DisplayName)'"; $b | Remove-NetFirewallRule } Get-NetFirewallRule -DisplayName $rule -ErrorAction SilentlyContinue | Remove-NetFirewallRule New-NetFirewallRule -DisplayName $rule -Direction Inbound -Program $exe -Action Allow -Profile Private,Domain -Protocol TCP | Out-Null Write-Host "added inbound allow rule '$rule' for $exe (private and domain networks)" } catch { Write-Host "could not change the firewall: $_" Start-Sleep -Seconds 5 exit 1 } Start-Sleep -Seconds 2