Skip to main content

Internet Access

Internet Access authorizes outbound connectivity from managed/protected sources to approved external destinations. The v2.4 datapath is TCP / HTTP / HTTPS CONNECT oriented. UDP Service Objects are not valid Internet Access selections.

Selector rules

A Managed Host may be used as a source. A Managed Host must not be used as a destination, directly or through a Network Group containing one.

Policy example

Internet Access uses the same BLACKLIST / WHITELIST and Enforcement model as Remote Access. DataRelay Link must not become an open proxy. The implementation validates destinations and protocol/port use, performs safe DNS handling where applicable, resists DNS rebinding and SSRF/private/local/metadata destinations, and fails closed on ambiguous unsafe state.
Last modified on September 22, 2026