liam -> doyle (cc todlando, hertz). Todlando's A3 objection looks right to me and I am ready for his option (a) the moment you rule. Standing by, nothing run. WHY I THINK HE IS RIGHT, independently rather than by agreement: A3's face is curl_exit=7, and a 7 requires the SYN to REACH the stack and be refused. A1 measured that the product's LAN half does not admit. So with the pair alone and the listener stopped, the packet is dropped at the filter and never reaches a stack that could refuse it — the fetch reads 28 for the SAME reason A0 read 28, which has nothing to do with refusal semantics. The arm would return a correct-looking number to a question it never got to ask. MY PART, ready on your word, exactly as before: one write, netsh add rule name="spt-w2-F" dir=in action=allow enable=yes profile=domain,private protocol=TCP localport=29470 remoteip=192.168.1.0/24, cheap predicate before and after, UTC stamps. THREE SEQUENCING COSTS, so you are pricing the whole thing and not just the write: 1. F MUST COME OUT AGAIN BEFORE A4, and A4's premise must be RE-VERIFIED after it, not carried forward from my 02:56:35Z reading. That reading is stale the moment F goes back in. I will re-census and quote the fresh one. 2. That is two more writes on the box tonight (add, delete) and two more census pairs. All cheap, all reversible, all mine as sole writer. 3. It puts a heavier load event between A2 and A4 in the timing table I own. I will keep logging walls, but rows after this point sit downstream of more activity than the earlier ones, so treat them accordingly. ONE THING THAT WILL NOT SUBSTITUTE, in case it is tempting as a cheaper route: a probe from the serving host to its OWN LAN address does not test this. Todlando measured own-LAN-address 200 at a moment the remote fetch was timing out, so that path is not subject to whatever drops the remote packet and cannot produce the refusal measurement A3 needs. The measurement has to originate off-box. If you would rather not spend the writes, the honest alternative is to record A3 as VOID-AS-DISPATCHED with todlando's reasoning attached and leave the requirement's non-sharing constraint UNMEASURED on Windows — which is worse for the record but costs nothing, and is a legitimate call given the hour. A4 premise as of 02:56:35Z and unchanged since: F absent, pair 2, port-29470 rules 2, hand rule 1, subject exe 0 Allow 0 Block. I have touched nothing since.