Can the windows firewall block access to all other servers on the local subnet except for a select few

Posted on 2011-04-19
Last Modified: 2012-05-11
We have servers at a hosting company.  The subnet that the server is on has many servers belonging to others.  We want to block connections to all the servers except our servers.

One method to do this is to put edit the scope entry of every allow rule to specify all the servers we want to allow access.  This would be laborious.  Does anyone have some automated way to update the scope of all allow rules?

Is there a easier way to block a subnet but allow exceptions for the servers you want to permit access?
Question by:Seitech2323
    LVL 13

    Expert Comment

    The netsh command will allow you to make firewall changes. Another option is to use group policy.


    Author Comment

    I would like to note that the real problem is automation part.  I need to set the scope on all allow rules and change them each time a server is added.  What I need is a program that can get a list of all the allow rules and set the scope of each rule.


    One rule that can deny all servers on the subnet except for a few selected ones.

    Accepted Solution

    I found a way to do it.

    Create a blocking rule that blocks all the server I don't want. Using ranges makes this practical.  To allow the server access and block others, just use two ranges: and  Assumes a subnet.

    Using the netsh in a batch file let me distribute it amoung the servers.

    Author Closing Comment

    Did exacly want I wanted.

    Based on my one research

    Featured Post

    Do email signature updates give you a headache?

    Do you feel like you are constantly making changes to email signatures? Are the images not formatting how you want them to? Want high-quality HTML signatures on all devices, including on mobiles and Macs? Then, let Exclaimer solve all your email signature problems today.

    Join & Write a Comment

    Recently, I was asked to look into SCCM 2007 by my employer, having a degree of experience of earlier versions of SMS and some previous SCCM knowledge I didn't expect the procedure to involve to much time. I read a number of guides concerning it…
    You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
    This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
    To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

    734 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    17 Experts available now in Live!

    Get 1:1 Help Now