Skip to navigation

Create firewall rules

Firewall rules control inbound traffic to your VMs. Each rule specifies an action, a protocol, a port, and a source. Rules are added to a firewall group, which is then attached to one or more VMs.

Before you begin

  • An active, verified IBEE Solutions organization
  • A firewall group — click Create Firewall Group on the Firewalls page if you don’t have one (Manage firewall groups)

Add a rule

1

Open Firewalls

In the portal sidebar, click Firewalls under Network & Security.

2

Select a firewall group

Click the firewall group you want to add rules to. The group opens with the IPv4 Rules tab active.

3

Add a new rule

Click Add rule. A new rule row appears with the following fields:

FieldDefaultOptions
Actionacceptaccept, drop
ProtocolTCPAny, TCP, UDP, ICMP
Port / App(empty)Port number, range (e.g. 8000-9000), or a common application. Applies to TCP and UDP only.
SourceAnywhereAnywhere (0.0.0.0/0), Custom
CIDR/IP0.0.0.0/0One or more CIDR blocks or IP addresses when the source is Custom
Notes(empty)Optional note describing the rule
4

Configure the rule

  1. Select the Action — accept to allow traffic, drop to block it.
  2. Choose a Protocol — Any, TCP, UDP, or ICMP.
  3. For TCP or UDP, enter a port number or range, or pick a common application: SSH (22), HTTP (80), HTTPS (443), MySQL (3306), PostgreSQL (5432), DNS (UDP 53), or MS RDP (3389).
  4. Set the Source — Anywhere allows all IPs, or choose Custom and enter one or more CIDR blocks or IP addresses.
  5. Optionally add a Note.
5

Save the rule

Click Save on the rule’s row. Each rule is saved individually and takes effect on all VMs attached to this firewall group.

IPv6 rules

IPv6 rules are coming soon. The IPv6 Rules tab does not accept rules yet.

Edit or delete a rule

  • To edit, change any field in the rule row and click Save on that row.
  • To delete, click the delete icon on the rule row. The rule is removed immediately — there is no separate save step.

System-managed rules cannot be edited or deleted. They have no Save or delete controls.

Example: allow web traffic

To allow HTTP and HTTPS from anywhere, add and save two rules:

ActionProtocolPortSource
acceptTCP80Anywhere
acceptTCP443Anywhere

Example: restrict SSH to an office IP

ActionProtocolPortSource
acceptTCP22Custom: 203.0.113.0/24

Troubleshooting

Cannot edit a rule System-managed rules are read-only. You can only edit or delete rules you created.

Changes not taking effect Make sure you clicked Save on each new or changed rule row. Unsaved rows are not applied.

Custom source validation error Enter valid CIDR notation (e.g. 10.0.0.0/8) or a single IP address. At least one CIDR or IP is required when using Custom source.