FLEET capabilities

I’m trying to understand how Fleet works, so I’ve digged through available resources regarding this topic and yet I can’t seem to find a clear answer for the following question:

Can I manage clusters locked behind a NAT or corporate Firewall by using Fleet?

Yes, the cluster agent opens an outbound connection to the management server; the clusters do not need to be directly reachable from anywhere.

Thank you for the quick response!

So there’s absolutely never the need for an inbound connection to the agent? All ports closed on the agent and it will work?