Issue: After installing Elements Agent (EPP for Computers or for Servers), VPN connection stopped working and is blocked by the Windows firewall.How to create a custom Elements Endpoint Protection profile to allow the VPN connection?Which ports need to be opened to allow PPTP, L2TP and IPSec VPN connection through the firewall?Resolution: In this case, you have to start by creating a custom profile that can be edited.Creating a custom profile: Log in to the Elements Security Center PortalOpen the Security configurations section from the menu on the leftGo to the Profiles pageSelect the circular symbol with three dots in the middle next to the profile you want to clonePress on the clone profileEnter the name and label of the new custom profile After creating a custom profile, you can start creating new firewall rules.Creating a new VPN firewall rule: Select the profile you want to useGo to the Firewall settings pageGo to Firewall rules and select add ruleEnter a name and description of the rule, e.g Allow VPN The ports and protocols that need to be allowed vary between each VPN connection type. Verify with your VPN provider the type of VPN connection you are using and which ports to open.To allow common PPTP VPN traffic: Allow PPTP tunnel maintenance traffic, open outbound TCP port 1723Allow PPTP tunneled data to pass through the router, open outbound protocol 47 (GRE)To allow common IPSec VPN traffic: Allow Internet Key Exchange (IKE), open UDP port 500 outboundAllow IPSec Network Address Translation (NAT-T), open UDP port 4500 outboundAllow Encapsulation Security Payload protocol (ESP), open protocol 50 outboundAllow Authentication Header protocol (AH), open protocol 51 outboundAllow IP-in-IP Encapsulation, open protocol 4 outbound. If IPSec IKEv2 VPN connection is not working after creating the above firewall rules, enable Allow unknown outbound connections from the profile and see if it helps. By default Windows firewall has unknown outbound connections allowed, while the WithSecure firewall profile will block them. To allow common L2TP VPN traffic: Allow L2TP traffic, open UDP port 1701 outboundAllow protocol 115 outbound Once the firewall rules have been created, the profile needs to be assigned to the target devices. Assigning a profile: Go to the Devices pageChoose the device(s) to which you want to assign a profile toClick on Assign > Assign profile Select the profile with the VPN firewall rules and click Assign