Origin isolation after protected-IP onboarding: removing bypass paths
Review old IPs, AAAA records, test domains and management access after onboarding.
Contents of this article
Traffic must actually traverse the protected path
Mitigation handles traffic traversing its entry point. A directly reachable original address can still expose the backend. Inventory public records, old addresses, test subdomains and alternative entry points.
Confirm allowed origin traffic from the actual design
Obtain the actual origin-source and protocol requirements before changing firewall rules. Retain health checks, backups and controlled management. Do not copy unrelated IP lists or block all traffic before validating the new path.
Check both IPv4 and IPv6
Changing A records may leave a direct AAAA record or another hostname pointing to the same origin. Validate both address families, all service names and any backend ports that should not be public.
Verify allowed and denied access
Verify critical actions through the protected entry and expected rejection of unauthorized direct access. Keep configuration backups and recovery steps, and repeat checks after origin or provider changes.
References
OWASP Denial of Service Cheat Sheet
