I hope you’re doing well.
I would like to follow up regarding a firewall issue we’ve encountered. Our internal server 10.184.190.25
attempted to connect to several external IP addresses using apt-get
and ssl
, but the connections were denied by the firewall.
Some of the destination IPs include:
151.101.130.132
151.101.2.132
185.125.190.81
91.189.91.81
192.100.77.186
From our initial review, these IPs appear to be associated with Canonical/Ubuntu repositories and CDNs like Fastly, which are typically used for system updates or package installations.
Could you please help clarify the following:
- Which firewall policy or rule is responsible for denying this traffic?
- Are these destinations considered safe and allowed in our environment?
- Would it be possible to whitelist or allow traffic to the necessary IP ranges, specifically for secure package management?
I’ve attached a screenshot of the firewall log for reference. Please let me know if further information is needed.
Thank you in advance for your assistance.