UTools for Windows System Administrators
UMove Help

Windows Firewall: Limit to Local Subnet

This advanced option will configure the Windows Firewall so that all network access to Active Directory will be limited to the local subnet where the computer is connected. By default any computer in the Internet can access Active Directory.

Windows Firewall must be enabled for this option to have any effect. Windows Firewall is enabled by default on Windows Server 2008 or later.