Technical Details

Protocols allowed

Egress traffic for the following IP protocols are not blocked:

TCP PortUse
22SSH (secure shell)
80HTTP (web access)
110POP3 (inbox access)
143IMAP (inbox access)
443HTTPS (secure web access)
465SMTPS (secure mail submission)
587SMTP (mail submission)
993IMAPS (secure inbox access)
995POP3S (secure inbox access)
1723PPTP (VPN)
5190AOL/AIM
UDP PortUse
500-599ISAKMP and other UDP VPN traffic
1701L2TP (VPN)
4500Cisco PIX (VPN)
Other IPUse
ipencap (4)IP Encapsulation (VPN)
esp (50)Encapsulating Security Payload (VPN)
gre (47)Generic Routing Encapsulation (VPN)
In particular, note that SMTP, FTP, IRC, and any ICMP traffic is blocked. Any requests for DNS or NTP will be redirected to an internal server (which will handle the request, so name lookups and clock updates will work as expected).