Yup, have had it working for a while.
There're a few things that need to be allowed in the network (incoming), and it's also rarely beneficial to block all outgoing traffic. Anyway, I'm pretty sure it's all documented, as I just showed it to our network people and they made it work (despite their default is also to block everything).
--
https://wheretofind.me/@NoSubstitute