Exit nodes
Route internet traffic through a private gateway or Orbit.
Enable a private exit#
- Edit a private gateway and set Exit Node to Enabled.
- Open Network → Access → Egress Policies.
- Choose tenant, role, group, or device scope.
- Select Required, Optional, or Disallowed.
- For allowed egress, choose automatic or pinned selection and any gateway or region constraints.
- Save and verify the device’s egress placement.
Orbit preferences apply only when Orbit is enabled and eligible regions are configured. A private exit gateway and Orbit are different paths.
Egress policy controls general internet routing. It does not replace an access policy for a private service, and it does not by itself enable Secure Web or Firewall rules.
If traffic stays local, confirm the gateway is Enabled for exit, the policy scope matches the device, and its priority wins.