Firewall
Use the firewall to control what traffic is allowed to or blocked from your VPS.
Where to find the settings
On the service page, under Service Management, you will usually find two areas:
- Firewall
- Firewall Options
important
Source IP enforcement
Traffic and IP usage are filtered by source. In practice, the VPS can route only the IP addresses assigned to it.
If you need to allow or route additional IP addresses, such as in BGP-related scenarios, open a support ticket before making the change.
Firewall
Use Firewall to create and manage rules.
Rule fields
| Field | What it controls | What you should enter |
|---|---|---|
Type | The direction or category of the rule. | Choose the rule type shown by the portal for the traffic you want to control. |
Action | Whether matching traffic is allowed or blocked. | Select the action that matches your policy, such as allow or deny. |
Interface | The network interface where the rule applies. | Use the interface that receives or sends the traffic you want to control. If you are unsure, review the service network layout first. |
Source | The origin IP address or network of the traffic. | Enter a single IP or CIDR range when you want to restrict where traffic can come from. |
Destination | The destination IP address or network of the traffic. | Enter a single IP or CIDR range when you want to control which destination is reachable. |
Macro | A shortcut for predefined service matching, when available. | Use it when the portal offers a service preset that matches your use case. |
Protocol | The protocol matched by the rule. | Select the protocol used by the application, such as TCP, UDP, or ICMP. |
Source Port | The originating port of the traffic. | Usually leave this empty unless you specifically need to match the client-side source port. |
Destination Port | The service port the traffic is trying to reach. | Enter the port used by the application, such as 22, 80, or 443. |
Enable | Whether the rule is active immediately. | Keep it enabled if you want the rule to take effect as soon as it is saved. |
Comment | A description for future review. | Add a short note describing why the rule exists. |
Firewall options
Use Firewall Options to review the overall firewall behavior for the VPS.
| Option | What it does | What to expect |
|---|---|---|
Enable Firewall | Turns the firewall policy on or off for the VPS. | When enabled, rule evaluation and default policies apply. |
Input Policy | Defines the default behavior for inbound traffic that does not match a specific rule. | If traffic is not matched by an allow rule, this setting decides whether it is accepted or blocked. |
Output Policy | Defines the default behavior for outbound traffic that does not match a specific rule. | If traffic is not matched by a specific outbound rule, this setting decides whether it is accepted or blocked. |
Common service examples
SSH -> Protocol: TCP | Destination Port: 22
HTTP -> Protocol: TCP | Destination Port: 80
HTTPS -> Protocol: TCP | Destination Port: 443
Best practices
- document internally the purpose of each important rule
- avoid creating rules without a comment when the interface allows descriptions
- review older rules to avoid unnecessary access
- make changes carefully when the VPS hosts production services
caution
Risk of lockout
An incorrect firewall rule can interrupt valid access, including administrative access. Review source, destination, protocol, and destination port before saving any change.
When to contact support
Open a ticket if:
- access to the VPS stops after a rule change
- the firewall appears active but behavior does not match the configuration
- you need to allow additional IP routing for scenarios such as BGP
- you need to validate the impact of a global policy before applying changes