-In the workload profiles environment, user-defined routes (UDRs) and securing outbound traffic with a firewall are supported. When using an external workload profiles environment, inbound traffic to Container Apps that use external Ingress routes through the public IP that exists in the [managed resource group](networking?tabs=azure-cli#workload-profiles-environment-1) rather than through your subnet. So locking down inbound traffic via NSG or Firewall on an external workload profiles environment is not supported. Learn more in the [networking concepts document](./networking.md#user-defined-routes-udr).
0 commit comments