Inside Pega Enterprise Infrastructure: Security and Encryption / Outbound ACL

Continuing our series of posts on Enterprise Infrastructure capabilities, featured in a dedicated tab within the Blueprint dashboard, this post explores Outbound ACL.

Client-Managed Outbound Access Control in Pega Cloud is a security capability that lets organizations control which external systems and endpoints a Pega Cloud environment can connect to, using a deny-by-default model where only explicitly approved destinations are allowed.

:white_check_mark: What it means:

It gives clients more granular control over network traffic moving from Pega Cloud to external systems and from client networks to Pega Cloud.

  • For outbound traffic: clients can define which external integration endpoints are allowed.
  • For inbound traffic: clients can request static inbound IP addresses dedicated to their Pega Cloud environments
  • It can be used with Pega Cloud Secure Connect or as a standalone add-on.

:white_check_mark: What It Does

  • Provides granular access control for traffic leaving Pega Cloud, such as integration traffic from Pega Infinity to a client network.
  • Supports client-managed outbound access control, where client-specific outbound connections are denied by default unless explicitly allowed.
  • Helps with data exfiltration protection by allowing only approved endpoints from each environment.
  • Enables granular segmentation between client environments and external systems, including separation between production and non-production systems.
  • Supports static inbound IP addresses to help manage traffic from a client data center to Pega Cloud.
  • Can improve routing and network performance when static IP addresses are used for public internet connectivity or selected Secure Connect options.

:white_check_mark: How It Works

Pega Cloud Advanced Networking includes two main capabilities:

  • Client-managed outbound access control
    • All client-specific outbound connections are denied by default.
    • Clients choose which endpoint connections to allow.
    • Up to 100 distinct integration endpoints per environment can be configured.
    • Changes are requested through a Change Request ticket in My Support Portal.
  • Static inbound IP addresses to Pega Cloud
    • Clients can request static inbound IP addresses dedicated to their Pega Cloud environments.
    • These IP addresses are shared across the client’s environments.
    • They help simplify network management and support more granular outbound access rules from the client network toward Pega Cloud.

:white_check_mark: Best Practices

  • Use client-managed outbound access control when you need strict control over which external systems each Pega Cloud environment can access.
  • Define approved endpoints carefully, including subnet, IP address, publicly resolvable DNS name, and port numbers when submitting a change request.
  • Use static inbound IP addresses when you need more consistent routing, simplified network configuration, or improved performance for public internet connectivity.
  • Work with your network/security team to align endpoint access, routing, and compliance requirements before requesting changes. (Suggested learner callout based on the documented network/security use case.)

:open_book: Technical Documentation: Pega Cloud Advanced Networking – docs.pega.com

1 Like