We have a requirement to detect and alert on a device trying to call an external or out of range IP address on a closed private network (no external routes at all).
i.e an address that ARP/DNS will deliberately not resolve. Could be a device that is legally on the network and happily talking to its legal neighbours but then every now and again sneaks in a connect request to its overseas manufacturer,
Whilst the network will never route etc. its a requirement to detect and alert that this has happened rather than just allowing it to quietly fail