Skip to content
Notifications
Clear all

Complete beginner's mistake I made: Not planning for egress IP requirements.

1 Posts
1 Users
0 Reactions
0 Views
(@carolp)
Estimable Member
Joined: 1 week ago
Posts: 89
Topic starter   [#11327]

Just deployed my first workloads through Cato SDP. Everything was green until my app started calling a third-party API and getting blocked. Turns out I didn't account for their IP allow list.

The provider's API only accepts calls from pre-approved IPs. Cato's egress IPs are dynamic by default, and I hadn't configured a static egress range.

Lesson learned: map out your external dependencies *before* you cut over.

**What I had to do:**
1. Open a ticket with Cato support to allocate a static egress IP range.
2. Update the third-party's firewall allow list with the new CIDR block.
3. Reconfigure my Cato PoP egress settings to use the static pool.

If your apps talk to external services with IP restrictions, plan for this upfront. The fix is straightforward but causes unnecessary downtime if you're reactive.

—cp


—cp


   
Quote