Firewall as a Service
IBEE Solutions Firewalls let you define inbound traffic rules and attach them to your VMs. Each firewall group contains a set of rules that control which traffic is allowed or dropped before it reaches your server. Firewalls are managed from the portal sidebar under Network & Security.
How firewalls work
- A firewall group is a named collection of inbound rules.
- Each rule specifies an action (accept or drop), a protocol, a port or port range, and a source.
- A firewall group can be attached to multiple VMs. A VM is in one firewall group at a time.
- New VMs are protected by a platform default firewall group. Attaching a VM to one of your firewall groups replaces the default for that VM; detaching it restores the default.
Firewall group structure
Select a firewall group to open it. It has three tabs:
Rule components
Each rule has the following fields:
Common application ports
The Port / App picker offers common services:
System-managed rules
Every new firewall group includes system-managed rules: all outbound traffic is allowed, and a final rule drops any inbound traffic that your rules don’t accept. System-managed rules have no Save or delete controls and cannot be edited or deleted. The firewall page lists inbound rules only.
Manage firewall groups
- Create — click Create Firewall Group, enter a Group name (e.g.
web-tier), and click Create Group. - Delete — open the group’s menu in the list, click Delete, and confirm. Deleting a firewall group cannot be undone.
- Copy ID — the group’s menu also copies the firewall group ID for use with the API.
Linked instances
The Linked Instances tab lists the VMs attached to the firewall group with their server name, public IP, status, and attach time.
- Attach — search for an active instance and click Attach. If the VM is already in another firewall group, it moves to this one.
- Detach — click Detach on the instance’s row. The VM returns to the platform default firewall group.
Best practices
- Allow only the ports you need — inbound traffic that no rule accepts is dropped.
- Use Custom source CIDRs to restrict access to known IP ranges instead of Anywhere.
- Keep SSH (port 22) access restricted to your office or VPN CIDR.
- Review linked instances periodically to ensure the right VMs are protected.
