GuideInformationBusiness ContinuityIT

Interpret Hyper-V extended ACL direction from the VM perspective

How should an extended virtual-switch ACL define traffic direction and scope?

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 2 min read
Executive summary

What you need to know

How should an extended virtual-switch ACL define traffic direction and scope?

Potentially affected

Administrators configuring extended port ACLs on Hyper-V VM network adapters.

DSE recommendation

Write the intended allowed and denied flows in a small matrix and have a second reviewer translate each into the documented direction convention.

Source facts

Microsoft documents extended ACLs applied to individual VM network adapters on a Hyper-V virtual switch. The rules can match source and destination addresses, protocol, and source and destination ports. In the documented direction convention, inbound means traffic received by the VM and outbound means traffic sent from it. Microsoft Learn.

Applicability

Identify the precise VM adapter and application flow before writing a rule. Review source, destination, protocol, and both port roles from that VM’s perspective. Keep an ACL on the virtual adapter distinct from a host firewall rule or a physical-network filter.

DSE recommendation

Write the intended allowed and denied flows in a small matrix and have a second reviewer translate each into the documented direction convention. Preserve the existing adapter ACLs and name the rollback owner. Pilot one application path, including the reply traffic and a deliberately prohibited source. Avoid broadening a rule simply because its first test was written in the wrong direction.

Verification

Generate the approved test flows from both sides of the VM boundary and record the effective rule and result. Confirm an excluded flow remains blocked while the required transaction works. Recheck the exact adapter association after configuration and document any other filter that affected the observed outcome.

Official references

Microsoft Learn: Create Security Policies with Extended Port Access Control Lists. Source reviewed September 8, 2026.

Primary reference

Review the official source

Create Security Policies with Extended Port Access Control Lists · Verified September 8, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE