When it come to Application ring-fencing validation, I would recommend that all of the components that need to communicate, on specific ports and protocols, within the ring-fence, and only those can. Additionally, only the workloads that need to communication outside of the App ring-fence with specific ports and protocols can. Any extraneous communication should not be allowed.