This feature enables the detection, analysis, and alert generation for external traffic (North-South). This can significantly improve your overall security posture. Faddom can give you a view of all servers with external connectivity (whether incoming or outgoing), along with the ability to set up blacklisted countries to be alerted on.
For this feature to work, you need to first enable external traffic for the relevant subnet(s) by following our guide How to Enable Data Collection for External Sources.
External Traffic Policy
The External Traffic Policy in Faddom controls how communication between internal systems and external networks is monitored and managed.
It provides visibility into both incoming and outgoing external traffic and supports two complementary configuration methods:
Apply Current as Policy - automatically builds a baseline policy from currently observed external connections.
Add New Rule - allows manual creation of rules specifying direction, source, target, and port.
Both automatic and manual rules can be used together to provide flexible and continuous monitoring of network boundaries.
Before using this feature, ensure external traffic collection is enabled for at least one subnet. To set this up, you can see our guide on How to Amend Subnet Discovery.
Once external traffic data is available, go to Settings → External Traffic Policy to review, generate, or adjust policies:
If you'd like to set up a policy for your internal subnets, please check out Subnet Traffic Policy configuration.
Setting Up Blacklisted Countries
To set up the blacklist of countries you wish to see, you go to Settings > External Traffic
You can select the countries by searching or scrolling and selecting the tick box. You can also collapse the continent grouping. As you select them they appear at the top and you can remove the country by clicking the X
Click Save
Updating the Public IPs
Faddom maintains a database to map public IP addresses to their respective countries. You can update this database under Settings -> External Traffic. There are options to update this database online or offline depending on whether you have internet access.
External Traffic Dashboard
On the main dashboard of Faddom, it will show you how many servers you are receiving external traffic for. The number is clickable and will take you to the External Traffic dashboard. You can also access it by selecting Secure > External Traffic. In this screen, you will see the servers listed along with the ports and countries of each connection.
If the blacklist has been set up, any countries that have been added to the blacklist will appear at the top with a pink background.
You can also see the results of what Faddom is found by navigating to the Security tab from the Server Properties
Click on a server from a map, search, or click on the properties icon - from any list view
In the properties panel, click Security in the bottom right
This will take you to the Server Security Dashboard where you can see all the security information on a server including any external traffic.

