This week Rapid7 announced the addition of Metamodules in Metasploit Pro v4.7. One of these modules, "Egress Firewall Testing", allows you to deduce outbound filtering rules from firewalls/routers. No doubt this functionality is really useful for example if we want to leave a reverse shell pointing to our machine. To get this, the metamodule "contacts to Rapid7-hosted server to test open ports and delivers the results in one easy report".
This module reminds me a little trick I usually do to get just the opposite, that is, to infer ingress firewall rules. In fact, this post could be the second part of the recent "Donde dejo mi bind shell" (spanish) but this time, with the advantage of Metasploit.