edgeos-bl-mgmt icon indicating copy to clipboard operation
edgeos-bl-mgmt copied to clipboard

What about applying these rules also for egress traffic?

Open gparmeggiani opened this issue 4 years ago • 1 comments

I'm thinking of the specific case of a malware talking to its C&C server via UDP. These rules won't block the upload traffic. Given the growing number of ransomware with the goal of stealing private data, a upload-only UDP connection should be enough for them for their job.

gparmeggiani avatar Dec 26 '20 14:12 gparmeggiani

The rules can apply wherever you apply them - that is entirely up to you.

If you want to add a rule to the 'out' direction on an interface (such as your WAN) then you absolutely can do so. There is nothing preventing that.

WaterByWind avatar Jan 08 '21 01:01 WaterByWind