---
title: Network egress
description: Choose what a sandbox may reach on the network, from the whole internet to an allowlist of addresses or nothing at all.
---

Every sandbox has an outbound network policy. You choose it when you create or fork the sandbox, and it cannot be changed afterwards.

| Mode | The sandbox can reach |
| --- | --- |
| `default` | the public internet |
| `allowlist` | only the IPv4 and IPv6 prefixes you list |
| `none` | nothing |

```sh
pols new --name web                                    # default: the public internet
pols new --name locked --egress allowlist --allow 203.0.113.10/32 --allow 2001:db8::/32
pols new --name offline --egress none
pols fork web --name web-offline --egress none         # a fork may choose its own policy
```

A fork keeps its source's policy unless you set one. Over the API, pass `egress` with `mode` and, for an allowlist, `allow` (up to 64 CIDR prefixes) to `POST /v1/sandboxes` or `.../fork`.

## How the modes behave

- The policy filters by IP address, not by host name. To allow a service, list the addresses or prefixes it uses. Single addresses need `/32` (IPv4) or `/128` (IPv6).
- In `allowlist` and `none`, the sandbox has no DNS resolver. For DNS in allowlist mode, allow a public resolver's address and configure the sandbox to use it, for example in `/etc/systemd/resolved.conf`.
- A policy applies to new connections.

Pick the mode with the sandbox's purpose in mind: `none` suits running untrusted code on data you copied in, `allowlist` suits a sandbox that should talk to one API or one database.

## Blocked in every mode

Some destinations are blocked whatever the policy says, and an allowlist entry that overlaps the built-in ranges is refused:

- other sandboxes, including your own;
- the sandbox host and the pols infrastructure, including `api.pols.so`, `ssh.pols.so` and `*.on.pols.so`, so the pols CLI and published ports cannot be used from inside a sandbox;
- private (RFC 1918), CGNAT and link-local addresses on the network, including the cloud metadata address `169.254.169.254`, and IPv6 unique-local and link-local addresses;
- multicast and broadcast;
- outgoing SMTP on TCP port 25. To send email from a sandbox, use your mail provider's submission port or HTTP API.

## Incoming traffic

Nothing on the internet can open a connection to a sandbox directly. The only ways in are the ones pols provides, and they work in every egress mode: [published ports](/access/ports/) and [SSH](/access/ssh/) through the edge, and the [desktop](/access/desktop/), commands, file transfers and computer use through the control plane.
