- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-11-2026 06:43 AM
Hello @Lakshminarayan ,
Greetings for the day.
Yes, your understanding is correct. In this scenario, the Host Firewall will allow the outbound traffic.
The Cortex XSIAM/XDR Host Firewall evaluates rules using a top-down approach, where the first rule that matches the traffic criteria is applied.
Here is how the evaluation logic works for your specific example:
Because the Inbound rule does not match the criteria for Outbound traffic, it does not block or interfere with it. The rules function independently based on the direction of the connection.
If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".
Thanks & Regards,
S. Subashkar Sekar