Outbound Connection Allowlist
The AIR Console checks destination hosts before opening outbound connections. Public internet hosts remain allowed. Private destinations must comply with the deployment-wide outbound CIDR policy, while always-blocked addresses remain blocked in every configuration.
The policy is a host-level administrative setting. It cannot be changed from the Console UI and is not configured separately for each organization, evidence repository, proxy, or integration.
If the Console rejects a host, it returns:
The specified host is not allowed for outbound connections.
The toast includes a View in Knowledge Base link to this article.
Which connections are checked
Section titled “Which connections are checked”The check applies to:
- SFTP and FTPS evidence repositories
- SMTP servers
- LDAP / Active Directory hosts
- Syslog / SIEM destinations
- HTTP destinations the Console connects to, including proxy hosts
If a hostname resolves to multiple IP addresses, every resolved address must be allowed.
Policy behavior
Section titled “Policy behavior”| Policy | Behavior |
|---|---|
| Empty allowlist | Allow private destinations, except always-blocked addresses |
| One or more CIDR ranges | Allow private destinations only when they fall within a listed range |
none | Block all private destinations |
List only the private subnets that host the services the Console needs (for example your SFTP server or internal SMTP relay). Separate ranges with commas. Do not list every RFC1918 range unless every one of those networks is a destination you intend the Console to reach — a wide allowlist reopens internal network reconnaissance from the Console.
Always-blocked addresses
Section titled “Always-blocked addresses”The following destinations stay blocked even if you add a matching CIDR:
- Loopback (for example
127.0.0.1,::1) - Unspecified addresses (for example
0.0.0.0,::) - Link-local addresses (for example
169.254.0.0/16) - Cloud instance metadata endpoints (
169.254.169.254,169.254.170.2, andfd00:ec2::254)
You cannot allow these ranges.
Manage the allowlist in v5.27 and later
Section titled “Manage the allowlist in v5.27 and later”Use the AIR CLI to list, add, or remove CIDR ranges. Run the commands on the Console host.
List the current policy
Section titled “List the current policy”sudo docker exec -ti binalyze-air-app-1 \ /air-cli outbound-cidr -a listThe command reports one of these states:
allowlistfollowed by the allowed CIDR rangesallowlist (empty — private/internal unrestricted)none (all private/internal outbound blocked)
Add a CIDR range
Section titled “Add a CIDR range”sudo docker exec -ti binalyze-air-app-1 \ /air-cli outbound-cidr -a add -c 10.20.30.0/24Repeat the command for each required range. The CLI validates CIDR syntax and does not add duplicate entries.
Adding a CIDR while the policy is none changes the policy to an allowlist containing that range.
Remove a CIDR range
Section titled “Remove a CIDR range”sudo docker exec -ti binalyze-air-app-1 \ /air-cli outbound-cidr -a remove -c 10.20.30.0/24The range must exactly match an existing entry.
Block every private destination
Section titled “Block every private destination”Use none with the add action:
sudo docker exec -ti binalyze-air-app-1 \ /air-cli outbound-cidr -a add -c noneThis changes the policy state to none and removes all existing CIDR ranges.
Apply changes
Section titled “Apply changes”CLI changes are saved in the Console database and persist across upgrades. The CLI normally applies changes immediately to the application and workers.
Check the command output:
Change applied live (workers notified).— No restart is required.Live refresh failed. Please restart the app for the settings to take effect.— Restart the Console:
cd /opt/binalyze-airdocker compose down && docker compose up -dUpgrade from an earlier version
Section titled “Upgrade from an earlier version”Before v5.27, the policy is configured with AIR_ALLOWED_OUTBOUND_CIDR_RANGES in the Console application .env file:
/opt/binalyze-air/volumes/app/binalyze-air/config/.env
During the first v5.27 startup, the Console reads this environment variable once and saves the resulting policy in the database:
| Environment variable value at first v5.27 startup | Saved policy |
|---|---|
| Empty or unset | Empty allowlist; private destinations are permitted except always-blocked addresses |
| Comma-separated CIDR list | Allow only the listed private ranges |
none | Block all private destinations |
For example:
AIR_ALLOWED_OUTBOUND_CIDR_RANGES=10.40.12.0/24,192.168.50.0/24After this one-time import, the live policy comes from the database. Later changes to AIR_ALLOWED_OUTBOUND_CIDR_RANGES are ignored. Use the AIR CLI to manage the policy.
Configure versions earlier than v5.27
Section titled “Configure versions earlier than v5.27”For an earlier version, add or edit AIR_ALLOWED_OUTBOUND_CIDR_RANGES in the Console application .env file. Separate multiple ranges with commas:
AIR_ALLOWED_OUTBOUND_CIDR_RANGES=10.40.12.0/24,192.168.50.0/24Use none to block all private destinations:
AIR_ALLOWED_OUTBOUND_CIDR_RANGES=noneAfter changing the file, restart the Console:
cd /opt/binalyze-airdocker compose down && docker compose up -dVerify the policy
Section titled “Verify the policy”Retry the connection that was blocked, such as validating an SFTP evidence repository or SMTP server. A host in an allowed CIDR should proceed to the destination service instead of returning The specified host is not allowed for outbound connections.
Confirm that private addresses outside the allowlist and always-blocked addresses such as 127.0.0.1 are rejected.