- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-22-2025 12:27 AM
Hi Team,
I have a doubt about Host Firewall rule evaluation. Let say i have a rule created to allow all internal application inbound traffic on specific port / Remote IP. In the same rule group if i create another outbound rule and action type : allow all outbound traffic on any port/IP how it will evaluate the rule. It means it will allow all outbound traffic right.
02-11-2026 06:43 AM
Hello @Lakshminarayan ,
Greetings for the day.
Yes, your understanding is correct. In this scenario, the Host Firewall will allow the outbound traffic.
The Cortex XSIAM/XDR Host Firewall evaluates rules using a top-down approach, where the first rule that matches the traffic criteria is applied.
Here is how the evaluation logic works for your specific example:
Because the Inbound rule does not match the criteria for Outbound traffic, it does not block or interfere with it. The rules function independently based on the direction of the connection.
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thanks & Regards,
S. Subashkar Sekar
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

