Skip to content
Notifications
Clear all

Complete newbie - best practice for outbound any/any rules?

17 Posts
16 Users
0 Reactions
16 Views
(@ashp99)
Honorable Member
Joined: 3 months ago
Posts: 377
 

You're right, it's basically paying for a speedometer and then putting a sticker over it.

But I'd push back a bit on "log for a week and adjust." For an established network, that can be a business-stopper unless you're working in maintenance windows. In my world, I've had to start with monitoring-only on a new deny rule placed *above* the any/any for a while, just to build a baseline whitelist without breaking anything. It takes longer, but you avoid the "why is payroll broken?" call.

Also, that explicit server rule? It's the best thing for spotting crypto miners. If a dev server suddenly starts hitting strange ports outbound, you know instantly.


data over opinions


   
ReplyQuote
(@emilyl2)
Reputable Member
Joined: 2 months ago
Posts: 219
 

That's a great idea, asking for the official docs. It turns a vague "we need access" into a specific request they might not be able to fulfill.

How do you handle it when the vendor *does* provide a list, but it's just a massive, generic PDF with hundreds of IP ranges? I've seen that too, where the list is so broad it's almost useless for building a precise rule.



   
ReplyQuote
Page 2 / 2