Airlock as a Service Knowledge Base

Egress policies

The Egress policies page controls which external destinations the IAM components of the selected tenant can access. By default, tenant IAMs cannot establish connections to external destinations. Egress policies explicitly allow an application module to connect to a specified destination using the configured network and application protocols.

Prerequisites

For information about the permissions required to manage egress traffic policies, see Roles and permissions.

Location in the Airlock Console

The Egress policies page can be managed on the Egress traffic policies page of the Airlock Console. To access this page, go to:
Configuration >> Egress policies


Outbound IP addresses of your Airlock IAM tenant

Traffic from your IAM tenant to your systems (for example, LDAP, databases, SMTP, or webhooks) originates from a fixed public IP address assigned to the region in which your tenant runs. If your firewall restricts inbound traffic by source IP address, allow the addresses listed below for their respective validity periods.


Azure Switzerland North (ch-1)

IP address

Valid from

Valid until

172.161.34.231

—

20 October 2026

74.161.192.85

20 October 2026

—

Allow all IP addresses that are valid at a given time. During a transition, keep the existing IP address allowed until its validity period ends. New IP addresses are published here in advance.


Allowed egress destinations

The Allowed egress destinations table lists the configured egress policies for the selected tenant. For each policy, the table shows:

  • Module – the application module to which the policy applies

  • Destination host/IP – the hostname or IP address of the permitted destination

  • Port – the destination port

  • Protocol – the network protocol used for the connection

  • App protocol – the application-level protocol used for the connection

Use the menu icon (⋮) of an existing policy to edit or delete it.


Adding an egress policy

  1. Click ⨁ Add rule.

    ➔ The Add egress policy dialog opens.

  2. Configure the following settings:

    • Module: Select the application module to which the egress policy applies.

    • Destination type: Select how the destination is specified:

      • Hostname: Enter the hostname of the destination without a protocol or path — e.g., api.example.com

      • IP address: Enter the IP address of the destination.
        ❗ Limitation  For UDP connections, specify the destination by IP address. UDP connections to destinations specified by hostname are not supported.

    • Port: Enter the destination port. Valid values are 1–65535.

    • Protocol: Select the network protocol to use.

    • App protocol: For TCP connections, select the application-level protocol to use.

  3. Click Add.

The egress policy is added to the Allowed egress destinations.


Editing an existing egress policy

  1. Click the menu icon (⋮) of the egress policy you want to update and select the Edit option.

    ➔ The Edit egress policy dialog opens.

  2. Change the required settings.

  3. Click Save.

The egress policy is updated.


Deleting an egress policy

  1. Click the menu icon (⋮) of the egress policy you want to remove and select the Delete option.

  2. Confirm the deletion.

The egress policy is removed and connections that relied on this policy are no longer permitted.