Continuing our series of posts on Enterprise Infrastructure capabilities, featured in a dedicated tab within the Blueprint dashboard, this post explores Outbound ACL.
Client-Managed Outbound Access Control in Pega Cloud is a security capability that lets organizations control which external systems and endpoints a Pega Cloud environment can connect to, using a deny-by-default model where only explicitly approved destinations are allowed.
What it means:
It gives clients more granular control over network traffic moving from Pega Cloud to external systems and from client networks to Pega Cloud.
- For outbound traffic: clients can define which external integration endpoints are allowed.
- For inbound traffic: clients can request static inbound IP addresses dedicated to their Pega Cloud environments
- It can be used with Pega Cloud Secure Connect or as a standalone add-on.
What It Does
- Provides granular access control for traffic leaving Pega Cloud, such as integration traffic from Pega Infinity to a client network.
- Supports client-managed outbound access control, where client-specific outbound connections are denied by default unless explicitly allowed.
- Helps with data exfiltration protection by allowing only approved endpoints from each environment.
- Enables granular segmentation between client environments and external systems, including separation between production and non-production systems.
- Supports static inbound IP addresses to help manage traffic from a client data center to Pega Cloud.
- Can improve routing and network performance when static IP addresses are used for public internet connectivity or selected Secure Connect options.
How It Works
Pega Cloud Advanced Networking includes two main capabilities:
- Client-managed outbound access control
- All client-specific outbound connections are denied by default.
- Clients choose which endpoint connections to allow.
- Up to 100 distinct integration endpoints per environment can be configured.
- Changes are requested through a Change Request ticket in My Support Portal.
- Static inbound IP addresses to Pega Cloud
- Clients can request static inbound IP addresses dedicated to their Pega Cloud environments.
- These IP addresses are shared across the client’s environments.
- They help simplify network management and support more granular outbound access rules from the client network toward Pega Cloud.
Best Practices
- Use client-managed outbound access control when you need strict control over which external systems each Pega Cloud environment can access.
- Define approved endpoints carefully, including subnet, IP address, publicly resolvable DNS name, and port numbers when submitting a change request.
- Use static inbound IP addresses when you need more consistent routing, simplified network configuration, or improved performance for public internet connectivity.
- Work with your network/security team to align endpoint access, routing, and compliance requirements before requesting changes. (Suggested learner callout based on the documented network/security use case.)
Technical Documentation: Pega Cloud Advanced Networking – docs.pega.com
