Windows Security Log Event ID 4957

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
 • Subcategory
Policy Change
 • MPSSVC Rule-Level Policy Change
Type Failure
Corresponding events
in Windows 2003
and before

4957: Windows Firewall did not apply the following rule

On this page

I routinely see this event logged throughout the day for Teredo and ICMP related rules. 

These rules are defined in Group Policy and in the Windows Firewall with Advanced Services MMC console.

Free Security Log Resources by Randy

Description Fields in 4957

Rule Information:

  •  ID: %1
  •  Name: %2

Error Information:

  •  Reason: %3 resolved to an empty set

Supercharger Free Edition

Supercharger's built-in Xpath filters leave the noise behind.



Examples of 4957

Windows Firewall did not apply the following rule:

Rule Information:

   ID: CoreNet-Teredo-In
   Name: Core Networking - Teredo (UDP-In)

Error Information:

   Reason: Local Port resolved to an empty set.

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection


Additional Resources