Hi I Hate Public Identities,
We are currently working on the official guidelines around the network configuration and will publish them around the official release of the product.
Some thoughts (not official guidance yet) as a cyber-security product we would want to see all traffic, IPv4 and IPv6, as a way to make sure that nothing has been enabled by the hacker.
HTH
ATA Team
Gershon Levitz [MSFT]