Skip to navigation

Firewall as a Service

IBEE Solutions Firewalls let you define inbound traffic rules and attach them to your VMs. Each firewall group contains a set of rules that control which traffic is allowed or dropped before it reaches your server. Firewalls are managed from the portal sidebar under Network & Security.

How firewalls work

  • A firewall group is a named collection of inbound rules.
  • Each rule specifies an action (accept or drop), a protocol, a port or port range, and a source.
  • A firewall group can be attached to multiple VMs. A VM is in one firewall group at a time.
  • New VMs are protected by a platform default firewall group. Attaching a VM to one of your firewall groups replaces the default for that VM; detaching it restores the default.

Firewall group structure

Select a firewall group to open it. It has three tabs:

TabContents
IPv4 RulesInbound rules for IPv4 traffic
IPv6 RulesComing soon — IPv6 rules can’t be added yet
Linked InstancesVMs attached to this firewall group, and controls to attach or detach them

Rule components

Each rule has the following fields:

FieldOptions
Actionaccept (allow traffic) or drop (block traffic)
ProtocolAny, TCP, UDP, or ICMP
Port / AppA port number, a range (e.g. 8000-9000), or a common application; TCP and UDP only
SourceAnywhere (0.0.0.0/0) or Custom CIDR/IP addresses
NotesOptional note describing the rule

Common application ports

The Port / App picker offers common services:

ApplicationProtocolPort
SSHTCP22
HTTPTCP80
HTTPSTCP443
MySQLTCP3306
PostgreSQLTCP5432
DNS (UDP)UDP53
MS RDPTCP3389

System-managed rules

Every new firewall group includes system-managed rules: all outbound traffic is allowed, and a final rule drops any inbound traffic that your rules don’t accept. System-managed rules have no Save or delete controls and cannot be edited or deleted. The firewall page lists inbound rules only.

Manage firewall groups

  • Create — click Create Firewall Group, enter a Group name (e.g. web-tier), and click Create Group.
  • Delete — open the group’s menu in the list, click Delete, and confirm. Deleting a firewall group cannot be undone.
  • Copy ID — the group’s menu also copies the firewall group ID for use with the API.

Linked instances

The Linked Instances tab lists the VMs attached to the firewall group with their server name, public IP, status, and attach time.

  • Attach — search for an active instance and click Attach. If the VM is already in another firewall group, it moves to this one.
  • Detach — click Detach on the instance’s row. The VM returns to the platform default firewall group.

Best practices

  • Allow only the ports you need — inbound traffic that no rule accepts is dropped.
  • Use Custom source CIDRs to restrict access to known IP ranges instead of Anywhere.
  • Keep SSH (port 22) access restricted to your office or VPN CIDR.
  • Review linked instances periodically to ensure the right VMs are protected.