A firewall is a network security device used to protect servers from network threats. The firewall monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules. You can set rules for all connections except port 25 for outbound traffic as it is blocked by default.
If you use a Load Balancer and your Virtual Machine is in a pool, configure its firewall by opening ports for receiving and transmitting data to the Load Balancer. For more information, refer to our guide "Create and configure a Load Balancer".
If you don’t create your custom firewall, the default firewall will be used.
1. Open a window to create a firewall. You can do in two ways:
2. Give your firewall a name.
3. Set Inbound rules which would define the allowed incoming traffic.
Click New rule and select one of the template rules or choose Custom to apply custom settings.
For Sources, set a specific IP address range in the CIDR format. Otherwise, the rule will be applied to all IP addresses.
4. Set the Outbound rules which would define the allowed outgoing traffic.
Please note that by default, outbound traffic over port 25 (TCP/UDP) is restricted, while all other outbound ports are open.
Click New rule and select one of the template rules or choose Custom to apply custom settings.
For Sources, set a specific IP address range in the CIDR format. Otherwise, the rule will be applied to all IP addresses.
5. (optional) Apply a firewall to a Virtual Machine by selecting it in the Apply to Instance drop-down list.
6. (optional) Add tags by switching on the Add tags toggle in the Additional options section and specifying headers and tags.
7. Click Create firewall.
If you don't specify which firewall to apply to your Virtual Machine, the default firewall will be applied.
The default firewall contains inbound rules, which allow the following traffic for IPv6 as for IPv4 addresses:
SSH connections over TCP protocol on port 22
Remote Desktop Protocol (RDP) connections over TCP and UDP protocols on port 3389.
Internet Control Message Protocol (ICMP) is allowed.
All outgoing connections are allowed.
1. Go to the Networking tab > Firewalls.
2. Find the required firewall, click the ⋯ menu on the right and select Rules.
1. Go to the Networking tab > Firewalls.
2. Find the required firewall, click the ⋯ menu on the right and select Instances.
You can’t delete a default firewall.
1. Go to the Networking tab > Firewalls.
2. Find the required firewall, click the ⋯ menu on the right and select Delete.
Please note that the Firewall feature is not supported for Bare Metal servers. Unlike Virtual Machines or other cloud services that can easily integrate with cloud-native firewalls, Bare Metal servers operate directly on physical hardware and are not subject to the same level of firewall management.
For network security, Bare Metal servers can use the following alternatives:
sudo iptables -A INPUT -p tcp --dport 22 -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 80 -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 443 -j ACCEPT
sudo iptables -A INPUT -i lo -j ACCEPT
sudo iptables -P INPUT DROP
For more information, please reach out to our support team for tailored DDoS Protection plans.
Was this article helpful?
Discover our offerings, including virtual instances starting from 3.7 euro/mo, bare metal servers, AI Infrastructure, load balancers, Managed Kubernetes, Function as a Service, and Centralized Logging solutions.