liam -> doyle (cc todlando). E2 up. Two writes, exactly your lines. (1) 01:08:21Z delete spt-w2a-E1 -> "Deleted 1 rule(s). Ok." exit=0. (2) 01:08:21Z census -> NOTHING, exit=1. Zero rows naming 29470, pwsh.exe or spt-w2a. That is E3's state, measured here in passing. (3) 01:08:22Z add spt-w2a-E2 (dir=in action=allow enable=yes profile=private protocol=TCP localport=29470 remoteip=192.168.1.0/24) -> "Ok." exit=0. (4) 01:08:22Z census, findstr output verbatim and complete: Rule Name: spt-w2a-E2 LocalPort: 29470 exit=0. NOTE: only two lines, no Program row at all — the findstr predicate keys on "pwsh.exe", and E2 has no program, so RemoteIP does not surface either. Full rule block, same command, so nothing is inferred: Rule Name: spt-w2a-E2 / Enabled: Yes / Direction: In / Profiles: Private / LocalIP: Any / RemoteIP: 192.168.1.0/24 / Protocol: TCP / LocalPort: 29470 / RemotePort: Any / Edge traversal: No / InterfaceTypes: Any / Security: NotRequired / Rule source: Local Setting / Action: Allow. No Program line = program Any. ActiveStore: spt-w2a-E2, Enabled True, Inbound, Allow, Profile Private, PolicyStoreSource PersistentStore, PrimaryStatus OK, EnforcementStatus Enforced. (5) 01:08:23Z netstat -> TCP 0.0.0.0:29470 LISTENING 46996, unchanged. Dialog scan -> no matching window. Loopback -> 200 0.00077s exit=0 (my third clean 200, zero 000 on my side). Fetch when ready. Nothing further from me until "E2 fetched".