Skip to main content

Firewall

Use the firewall to control what traffic is allowed to or blocked from your VPS.

Where to find the settings​

On the service page, under Service Management, you will usually find two areas:

  • Firewall
  • Firewall Options
important

Source IP enforcement

Traffic and IP usage are filtered by source. In practice, the VPS can route only the IP addresses assigned to it.

If you need to allow or route additional IP addresses, such as in BGP-related scenarios, open a support ticket before making the change.

Firewall​

Use Firewall to create and manage rules.

Rule fields​

FieldWhat it controlsWhat you should enter
TypeThe direction or category of the rule.Choose the rule type shown by the portal for the traffic you want to control.
ActionWhether matching traffic is allowed or blocked.Select the action that matches your policy, such as allow or deny.
InterfaceThe network interface where the rule applies.Use the interface that receives or sends the traffic you want to control. If you are unsure, review the service network layout first.
SourceThe origin IP address or network of the traffic.Enter a single IP or CIDR range when you want to restrict where traffic can come from.
DestinationThe destination IP address or network of the traffic.Enter a single IP or CIDR range when you want to control which destination is reachable.
MacroA shortcut for predefined service matching, when available.Use it when the portal offers a service preset that matches your use case.
ProtocolThe protocol matched by the rule.Select the protocol used by the application, such as TCP, UDP, or ICMP.
Source PortThe originating port of the traffic.Usually leave this empty unless you specifically need to match the client-side source port.
Destination PortThe service port the traffic is trying to reach.Enter the port used by the application, such as 22, 80, or 443.
EnableWhether the rule is active immediately.Keep it enabled if you want the rule to take effect as soon as it is saved.
CommentA description for future review.Add a short note describing why the rule exists.

Firewall options​

Use Firewall Options to review the overall firewall behavior for the VPS.

OptionWhat it doesWhat to expect
Enable FirewallTurns the firewall policy on or off for the VPS.When enabled, rule evaluation and default policies apply.
Input PolicyDefines the default behavior for inbound traffic that does not match a specific rule.If traffic is not matched by an allow rule, this setting decides whether it is accepted or blocked.
Output PolicyDefines the default behavior for outbound traffic that does not match a specific rule.If traffic is not matched by a specific outbound rule, this setting decides whether it is accepted or blocked.

Common service examples​

SSH -> Protocol: TCP | Destination Port: 22
HTTP -> Protocol: TCP | Destination Port: 80
HTTPS -> Protocol: TCP | Destination Port: 443

Best practices​

  • document internally the purpose of each important rule
  • avoid creating rules without a comment when the interface allows descriptions
  • review older rules to avoid unnecessary access
  • make changes carefully when the VPS hosts production services
caution

Risk of lockout

An incorrect firewall rule can interrupt valid access, including administrative access. Review source, destination, protocol, and destination port before saving any change.

When to contact support​

Open a ticket if:

  • access to the VPS stops after a rule change
  • the firewall appears active but behavior does not match the configuration
  • you need to allow additional IP routing for scenarios such as BGP
  • you need to validate the impact of a global policy before applying changes