In some scenarios, certain applications within a data center may need to access external services but avoid accessing certain internal services. These restricted internal services may share the same IP address as external services. In such cases, you can configure an IP address allowlist in a custom security policy (allow policy) to permit internal applications to access services outside the data center, and deselect Configure traffic rule allowing ingress traffic for destination VMs to prevent access to internal services.
For example, internal applications VM1 and VM2 need to access the Internet but should not access internal service VM3. To meet this requirement, create an allow policy for VM1 and VM2, add 0.0.0.0/0 to the egress allowlist, and deselect Configure traffic rule allowing ingress traffic for destination VMs.
