I would like to restrict the CIFS subsystem to listen not only on one of the box's two network interfaces (done, works great) - but also respond only to connection requests sourced from specific networks on the wire.
Yes, however these sorts of things can be done simply and internally with most other services like apache and samba … I am hoping it can be configured internally, otherwise your idea is definitely worth pursuing.
This is the IP held by that interface. That pretty much took care of it. However, I never went further regarding limiting the source connections. Our firewall takes care of that from the outside.