• TomThomson (10/11/2014)


    Ville-Pekka Vahteala (10/10/2014)


    More updated link.

    http://technet.microsoft.com/en-us/library/dd734783(v=ws.10).aspx

    After reading I am still convinced that one can have inbound rule for limited list of ips on local port.

    well, the second sentence on that page says "This context is the command-line equivalent to the Inbound Rules and Outbound Rules nodes of the Windows Firewall with Advanced Security MMC snap-in." In other words, if he has the new firewall called "Windows Firewall with Advance Security" he can do it. If he has the old firewall called Windows Firewall he can't.

    I don't know why you excluded the last paragraph of my message when you quoted it; it said exactlty that - he can do it with the new firewall and not with the old one. As you previously reference a page for teh old firewall (a page that says very clearly that you can't do it) I had assumed that the discussion was about someone stuck with the old firewall; I don't know which one he has.

    I did not exlude paragraph by choice. Maybe you edit message and added the last line there. It shows edited and I did reply quite quickly.

    Even my previous link which is for older server version has option to have custom list as scope. I still think that one can do it with windows firewall. Maybe it is not that easy from GUI, but it is still doable.

    Custom list

    This setting allows you to specify one or more IPv4 addresses or IPv4 address ranges separated by commas (with no spaces). IPv4 address ranges typically correspond to subnets. For IPv4 addresses, type the IPv4 address in dotted decimal notation. For IPv4 address ranges, you can specify the range using a dotted decimal subnet mask or a prefix length. When you use a dotted decimal subnet mask, you can specify the range as an IPv4 network ID (such as 10.47.81.0/255.255.255.0) or by using an IPv4 address within the range (such as 10.47.81.231/255.255.255.0). When you use a network prefix length, you can specify the range as an IPv4 network ID (such as 10.47.81.0/24) or by using an IPv4 address within the range (such as 10.47.81.231/24). The following is an example custom list: 10.91.12.56,10.7.14.9/255.255.255.0,10.116.45.0/255.255.255.0,172.16.31.11/24,172.16.111.0/24

    I corrected one typo.