What you need to know
How should an extended virtual-switch ACL define traffic direction and scope?
Potentially affected
Administrators configuring extended port ACLs on Hyper-V VM network adapters.
DSE recommendation
Write the intended allowed and denied flows in a small matrix and have a second reviewer translate each into the documented direction convention.
Source facts
Microsoft documents extended ACLs applied to individual VM network adapters on a Hyper-V virtual switch. The rules can match source and destination addresses, protocol, and source and destination ports. In the documented direction convention, inbound means traffic received by the VM and outbound means traffic sent from it. Microsoft Learn.
Applicability
Identify the precise VM adapter and application flow before writing a rule. Review source, destination, protocol, and both port roles from that VM’s perspective. Keep an ACL on the virtual adapter distinct from a host firewall rule or a physical-network filter.
DSE recommendation
Write the intended allowed and denied flows in a small matrix and have a second reviewer translate each into the documented direction convention. Preserve the existing adapter ACLs and name the rollback owner. Pilot one application path, including the reply traffic and a deliberately prohibited source. Avoid broadening a rule simply because its first test was written in the wrong direction.
Verification
Generate the approved test flows from both sides of the VM boundary and record the effective rule and result. Confirm an excluded flow remains blocked while the required transaction works. Recheck the exact adapter association after configuration and document any other filter that affected the observed outcome.
Official references
Microsoft Learn: Create Security Policies with Extended Port Access Control Lists. Source reviewed September 8, 2026.
Review the official source
Create Security Policies with Extended Port Access Control Lists · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE