Windows Windows Server

Restrict IP Address Range on Windows PC

Windows-Logo

The security of your Windows PC is very important. You can restrict a certain IP Address range from establishing an inbound connection to your computer. In this post, I show you how to restrict IP Address range on Windows PC that can remotely connect to my Windows PC. This can be achieved through the use of the Windows Defender Firewall advanced option. An IP address (Internet Protocol address) is a unique numerical label assigned to each device connected to a computer network that uses the Internet Protocol for communication. It serves as a unique identifier for devices to communicate with each other over a network. Learn how to Add a Printer Using an IP Address in Windows 11.

What are an IP Address, and MAC address?

An IP address consists of a series of numbers separated by dots, such as 192.168.1.1. There are two versions of IP addresses currently in use, IPv4 and IPv6. IPv4 addresses consist of 32 bits, while IPv6 addresses consist of 128 bits. IP Address is different from MAC Address which stands for Media Access Control address. MAC address is a unique identifier assigned to a network interface controller (NIC) for use as a network address in communications within a network segment. If you’re facing the problem of IP Address not being reachable, review the IP Address UNREACHABLE: HTTP connection pool Max exceeded post. You can also check out how to configure a Windows client to obtain an IP Address automatically from a DHCP Server

The MAC address is a hardware address that is assigned to the physical network interface card (NIC) at the time of manufacturing. It is a 48-bit address and is usually represented in hexadecimal formats, such as 00:1A:2B:3C:4D:5E.

MAC address (Media Access Control address) is a unique identifier assigned to a network interface controller (NIC) for use as a network address in communications within a network segment. The MAC address is a hardware address that is assigned to the physical network interface card (NIC) at the time of manufacturing. It is a 48-bit address and usually represented in hexadecimal format, such as 00:1A:2B:3C:4D:5E.

MAC addresses are used for communication between devices on the same network segment, such as a local area network (LAN). Unlike IP addresses, which can change depending on network configuration, MAC addresses are fixed and do not change. 

How to Restrict IP Address

You can go through the following steps to achieve your configuration steps. Please see SSL Encrypted Communications explained, How to restrict access to removable Storage Drives, How to create a Windows firewall rule on Windows, SSL Encrypted Communications explained, How to Restrict Access to USB Drives, how to restrict additional Microsoft Support Diagnostic Tool downloads in Windows, and How to protect Remote Desktop credentials with Windows Defender Remote Credential Guard or Restricted Admin Mode.

Step 1:    Go to Control Panel – > System and Security

System-and-Security-options
System-Control-Panel

Step 2: Next, go to Windows Defender Firewall ->  Advanced settings.

Step 3:     Choose the Inbound Rules -> New Rules.

Inbound-rules-new-rule
Inbound Rule -> New Rule

Step 4: Choose Port, and click next.

choose-TCP-port
Choosing Port Option

Step 5: Select TCP and Specific local ports, type 3389 which is the port number for RDP in the textbox and click on Next.

select-specific-ports
Choose TCP

Step 6:     In the Action tab, choose to Allow the connection and click on Next. Please see the Top 10 communication software for Mac 202, and how to Fix SSO sign-in and non-routable domain issues.

Allow-connection
Allowing Connection

6.     In the Profile section, make sure you check  Domain, Private, and Public in the checkbox and click on Next.

check-domain-private-public
Selecting the Appropriate profiles

7.     In the Name tab, type a specific name for this policy and click on finish. The rule will appear in the list. I typed allow-tcp-connection as the name of the policy. You can use the name you prefer.

Type-the-and-click-finish
Provide the Policy’s Name

Restricting or Allowing IP Address Range in Windows Firewall

With the rule we have just defined, we can restrict access to a certain range of IP Addresses to allow them to communicate with our PC. To do this, follow the below steps;

Step 1: Check for and double-click the rule you created in the previous section, and choose the Scope tab.

Add-IP-Address-main

Step 2:     Choose These IP addresses in the Remote IP address as shown in the above screenshot, and click add. In the next screen, type the address or subnet in the textbox. Or choose “local subnet” under the Predefined set of computers.

Note: You can choose to specify a range of IP Address or enter a single IP or subnet. For security reasons, do not expose your IP Addresses in the public except for demo purpose. 

Click on Okay to add the IP Addresses and click Apply and Okay to apply the scope.

Click-Apply-and-okay
Click on Apply and Okay

I hope you found this blog post helpful on how to Restrict IP Address Range on Windows PC. If you have any questions, please let me know in the comment section.

Subscribe
Notify of
guest

0 Comments
Inline Feedbacks
View all comments
0
Would love your thoughts, please comment.x
()
x