proxy in the middle (but cert pinning problems)
or DNS filtering? (but agent could have "memorized" stable IP)
Memorized IP: doesn't work, the vm can only connect to an IP if it came from a DNS lookup of an allowed name. Any other IP is blocked.
A bit of "shared responsibility" philosophy kicking through but I try to have good defaults