<!-- https://zerolog.ch/news/limits-on-outbound-traffic -->
# Outbound traffic now has limits, not only an allow-list

2026-10-06 · Security

> A handful of service ports are closed for every workspace, and traffic that looks like scanning or password guessing slows down and then stops.

Until now a workspace's internet access was judged by one question: may this account reach that destination? Nothing asked how much, how fast, or how many places at once. An allowed host could still be hammered, and a port nobody needs stayed open because no rule mentioned it. \*\*A few ports are closed for everyone.\*\* Mail delivery, Windows file sharing, Telnet and a few old services that outbound traffic only ever uses for spam or password guessing. This is not a setting. No permission level and no "always allow" opens them. Port 22 stays open, because git over SSH is real work, but a workspace may reach twelve different hosts on it per minute, not a thousand. \*\*Patterns are counted, not tool names.\*\* Forbidding a scanner would be theatre: a port scan is twenty lines of Python. So the check is on the traffic itself. Many different destinations in a short time, many ports on one host, the same service tried again and again, mostly refused connections, a steady upload that never ends. Each raises a number, and the number decays on its own. A single odd minute fades; a pattern that holds does not. \*\*The response comes in steps.\*\* First only counting. Then narrower limits and a bandwidth cap, where connections are slowed rather than cut mid-transfer. Then no new destinations, while the ones in use keep working. Only at the top does traffic stop, and even then the model provider stays reachable, so the chat that explains it still works. The boundary sits between the workspace and the network, not inside the model. ZeroLog runs uncensored models on purpose, and what a model will say should not decide what a socket can do. Testing your own servers still works: prove you own the domain and a scan may run in that scope. None of this is logged; the counters live in memory and do not survive a restart.
