Skip to content

Outbound Connection Allowlist

The AIR Console checks destination hosts before opening outbound connections. Public internet hosts remain allowed. Private destinations must comply with the deployment-wide outbound CIDR policy, while always-blocked addresses remain blocked in every configuration.

The policy is a host-level administrative setting. It cannot be changed from the Console UI and is not configured separately for each organization, evidence repository, proxy, or integration.

If the Console rejects a host, it returns:

The specified host is not allowed for outbound connections.

The toast includes a View in Knowledge Base link to this article.

The check applies to:

  • SFTP and FTPS evidence repositories
  • SMTP servers
  • LDAP / Active Directory hosts
  • Syslog / SIEM destinations
  • HTTP destinations the Console connects to, including proxy hosts

If a hostname resolves to multiple IP addresses, every resolved address must be allowed.

PolicyBehavior
Empty allowlistAllow private destinations, except always-blocked addresses
One or more CIDR rangesAllow private destinations only when they fall within a listed range
noneBlock all private destinations

List only the private subnets that host the services the Console needs (for example your SFTP server or internal SMTP relay). Separate ranges with commas. Do not list every RFC1918 range unless every one of those networks is a destination you intend the Console to reach — a wide allowlist reopens internal network reconnaissance from the Console.

The following destinations stay blocked even if you add a matching CIDR:

  • Loopback (for example 127.0.0.1, ::1)
  • Unspecified addresses (for example 0.0.0.0, ::)
  • Link-local addresses (for example 169.254.0.0/16)
  • Cloud instance metadata endpoints (169.254.169.254, 169.254.170.2, and fd00:ec2::254)

You cannot allow these ranges.

Use the AIR CLI to list, add, or remove CIDR ranges. Run the commands on the Console host.

Terminal window
sudo docker exec -ti binalyze-air-app-1 \
/air-cli outbound-cidr -a list

The command reports one of these states:

  • allowlist followed by the allowed CIDR ranges
  • allowlist (empty — private/internal unrestricted)
  • none (all private/internal outbound blocked)
Terminal window
sudo docker exec -ti binalyze-air-app-1 \
/air-cli outbound-cidr -a add -c 10.20.30.0/24

Repeat the command for each required range. The CLI validates CIDR syntax and does not add duplicate entries.

Adding a CIDR while the policy is none changes the policy to an allowlist containing that range.

Terminal window
sudo docker exec -ti binalyze-air-app-1 \
/air-cli outbound-cidr -a remove -c 10.20.30.0/24

The range must exactly match an existing entry.

Use none with the add action:

Terminal window
sudo docker exec -ti binalyze-air-app-1 \
/air-cli outbound-cidr -a add -c none

This changes the policy state to none and removes all existing CIDR ranges.

CLI changes are saved in the Console database and persist across upgrades. The CLI normally applies changes immediately to the application and workers.

Check the command output:

  • Change applied live (workers notified). — No restart is required.
  • Live refresh failed. Please restart the app for the settings to take effect. — Restart the Console:
Terminal window
cd /opt/binalyze-air
docker compose down && docker compose up -d

Before v5.27, the policy is configured with AIR_ALLOWED_OUTBOUND_CIDR_RANGES in the Console application .env file:

/opt/binalyze-air/volumes/app/binalyze-air/config/.env

During the first v5.27 startup, the Console reads this environment variable once and saves the resulting policy in the database:

Environment variable value at first v5.27 startupSaved policy
Empty or unsetEmpty allowlist; private destinations are permitted except always-blocked addresses
Comma-separated CIDR listAllow only the listed private ranges
noneBlock all private destinations

For example:

Terminal window
AIR_ALLOWED_OUTBOUND_CIDR_RANGES=10.40.12.0/24,192.168.50.0/24

After this one-time import, the live policy comes from the database. Later changes to AIR_ALLOWED_OUTBOUND_CIDR_RANGES are ignored. Use the AIR CLI to manage the policy.

For an earlier version, add or edit AIR_ALLOWED_OUTBOUND_CIDR_RANGES in the Console application .env file. Separate multiple ranges with commas:

Terminal window
AIR_ALLOWED_OUTBOUND_CIDR_RANGES=10.40.12.0/24,192.168.50.0/24

Use none to block all private destinations:

Terminal window
AIR_ALLOWED_OUTBOUND_CIDR_RANGES=none

After changing the file, restart the Console:

Terminal window
cd /opt/binalyze-air
docker compose down && docker compose up -d

Retry the connection that was blocked, such as validating an SFTP evidence repository or SMTP server. A host in an allowed CIDR should proceed to the destination service instead of returning The specified host is not allowed for outbound connections.

Confirm that private addresses outside the allowlist and always-blocked addresses such as 127.0.0.1 are rejected.