# Interpret Hyper-V extended ACL direction from the VM perspective

> How should an extended virtual-switch ACL define traffic direction and scope?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-217-interpret-hyper-v-extended-acl-direction-from-the-vm-perspective/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:34+00:00
- Modified: 2026-09-08T18:29:33+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

How should an extended virtual-switch ACL define traffic direction and scope?

## Potentially affected

Administrators configuring extended port ACLs on Hyper-V VM network adapters.

## DSE recommendation

Write the intended allowed and denied flows in a small matrix and have a second reviewer translate each into the documented direction convention.

## Article

## Source facts

Microsoft documents extended ACLs applied to individual VM network adapters on a Hyper-V virtual switch. The rules can match source and destination addresses, protocol, and source and destination ports. In the documented direction convention, inbound means traffic received by the VM and outbound means traffic sent from it. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/create-security-policies-extended-port-access-control-lists).

## Applicability

Identify the precise VM adapter and application flow before writing a rule. Review source, destination, protocol, and both port roles from that VM’s perspective. Keep an ACL on the virtual adapter distinct from a host firewall rule or a physical-network filter.

## DSE recommendation

Write the intended allowed and denied flows in a small matrix and have a second reviewer translate each into the documented direction convention. Preserve the existing adapter ACLs and name the rollback owner. Pilot one application path, including the reply traffic and a deliberately prohibited source. Avoid broadening a rule simply because its first test was written in the wrong direction.

## Verification

Generate the approved test flows from both sides of the VM boundary and record the effective rule and result. Confirm an excluded flow remains blocked while the required transaction works. Recheck the exact adapter association after configuration and document any other filter that affected the observed outcome.

## Official references

[Microsoft Learn: Create Security Policies with Extended Port Access Control Lists](https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/create-security-policies-extended-port-access-control-lists). Source reviewed September 8, 2026.

## Primary reference

- Name: Create Security Policies with Extended Port Access Control Lists
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/create-security-policies-extended-port-access-control-lists
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Interpret Hyper-V extended ACL direction from the VM perspective,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-217-interpret-hyper-v-extended-acl-direction-from-the-vm-perspective/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
