Restricting public access to sandbox URLs
By default, sandbox URLs are publicly accessible. You can restrict access to require authentication using theallowPublicTraffic / allow_public_traffic option:
allowPublicTraffic / allow_public_traffic is set to a falsy value, all requests to the sandbox’s public URLs must include the e2b-traffic-access-token header with the value from sandbox.trafficAccessToken / sandbox.traffic_access_token.
Code Interpreter sandboxes
The Code Interpreter server listens on port49999 and runs any code sent to it. On a sandbox with public access, anyone who has the port 49999 URL can run code in the sandbox and read its files. If you only call the sandbox through the SDK, nothing else needs that URL, so restrict public access. The Code Interpreter SDK sends the traffic access token for you, so runCode / run_code keeps working:
Running a firewall inside the sandbox
E2B already blocks every sandbox from sending outbound traffic to private and link-local address ranges. This is enforced outside the guest, applies to every sandbox, and cannot be disabled, so you do not need your own in-sandbox rules to block these ranges:10.0.0.0/8100.64.0.0/10127.0.0.0/8169.254.0.0/16172.16.0.0/12192.168.0.0/16
iptables -A OUTPUT -d 10.0.0.0/8 -j DROP) without allowing established and related connections ahead of it, you will cut that control channel and the sandbox will lose contact with the SDK. During a template build this surfaces as the start command failing its readiness check.
To restrict which public destinations a sandbox can reach, use the built-in network configuration (allowInternetAccess, denyOut, allowOut) rather than in-sandbox firewall rules.