Allow egress rules to select a protocol without requiring a specific port, and allow a port to apply to both TCP and UDP.
For a chosen destination, support these combinations:
| Rule |
Expected behaviour |
| TCP, no port specified |
Match TCP traffic on all destination ports, but not UDP or ICMP. |
| UDP, no port specified |
Match UDP traffic on all destination ports, but not TCP or ICMP. |
| ICMP, no port specified |
Match ICMP traffic without also allowing TCP or UDP. |
any, no port specified |
Preserve the existing all-protocol behaviour. |
any, port 443 |
Match TCP and UDP on destination port 443, but not ICMP. |
Apply these combinations to both allow and deny rules. Explicit deny must continue to take precedence over allow.
Verify allowed traffic and nearby cases that must remain blocked.
MXC schema requirement: network.egress.allow[].ports and network.egress.deny[].ports, where protocol supports tcp, udp, icmp and any, and port is optional.
Allow egress rules to select a protocol without requiring a specific port, and allow a port to apply to both TCP and UDP.
For a chosen destination, support these combinations:
any, no port specifiedany, port443Apply these combinations to both allow and deny rules. Explicit deny must continue to take precedence over allow.
Verify allowed traffic and nearby cases that must remain blocked.
MXC schema requirement:
network.egress.allow[].portsandnetwork.egress.deny[].ports, whereprotocolsupportstcp,udp,icmpandany, andportis optional.