Origin isolation after protected-IP onboarding: removing bypass paths

Review old IPs, AAAA records, test domains and management access after onboarding.

Contents of this article

Traffic must actually traverse the protected path

Mitigation handles traffic traversing its entry point. A directly reachable original address can still expose the backend. Inventory public records, old addresses, test subdomains and alternative entry points.

Confirm allowed origin traffic from the actual design

Obtain the actual origin-source and protocol requirements before changing firewall rules. Retain health checks, backups and controlled management. Do not copy unrelated IP lists or block all traffic before validating the new path.

Check both IPv4 and IPv6

Changing A records may leave a direct AAAA record or another hostname pointing to the same origin. Validate both address families, all service names and any backend ports that should not be public.

Verify allowed and denied access

Verify critical actions through the protected entry and expected rejection of unauthorized direct access. Keep configuration backups and recovery steps, and repeat checks after origin or provider changes.

References

OWASP Denial of Service Cheat Sheet

Related products and onboarding

View products and onboarding information

Back to industry insights Contact technical support