> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.ibee.co.in/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/docs/_mcp/server.

# Create firewall rules

> Add inbound firewall rules to control which traffic reaches your IBEE Solutions VMs.

Firewall rules control inbound traffic to your VMs. Each rule specifies an action, a protocol, a port, and a source. Rules are added to a firewall group, which is then attached to one or more VMs.

## Before you begin

* An active, verified IBEE Solutions organization
* A firewall group — click **Create Firewall Group** on the Firewalls page if you don't have one ([Manage firewall groups](/docs/network-security/firewalls#manage-firewall-groups))

## Add a rule

### Open Firewalls

In the portal sidebar, click **Firewalls** under **Network & Security**.

### Select a firewall group

Click the firewall group you want to add rules to. The group opens with the **IPv4 Rules** tab active.

### Add a new rule

Click **Add rule**. A new rule row appears with the following fields:

| Field          | Default     | Options                                                                                      |
| -------------- | ----------- | -------------------------------------------------------------------------------------------- |
| **Action**     | accept      | accept, drop                                                                                 |
| **Protocol**   | TCP         | Any, TCP, UDP, ICMP                                                                          |
| **Port / App** | (empty)     | Port number, range (e.g. `8000-9000`), or a common application. Applies to TCP and UDP only. |
| **Source**     | Anywhere    | Anywhere (`0.0.0.0/0`), Custom                                                               |
| **CIDR/IP**    | `0.0.0.0/0` | One or more CIDR blocks or IP addresses when the source is Custom                            |
| **Notes**      | (empty)     | Optional note describing the rule                                                            |

### Configure the rule

1. Select the **Action** — **accept** to allow traffic, **drop** to block it.
2. Choose a **Protocol** — Any, TCP, UDP, or ICMP.
3. For TCP or UDP, enter a port number or range, or pick a common application: SSH (22), HTTP (80), HTTPS (443), MySQL (3306), PostgreSQL (5432), DNS (UDP 53), or MS RDP (3389).
4. Set the **Source** — **Anywhere** allows all IPs, or choose **Custom** and enter one or more CIDR blocks or IP addresses.
5. Optionally add a **Note**.

### Save the rule

Click **Save** on the rule's row. Each rule is saved individually and takes effect on all VMs attached to this firewall group.

## IPv6 rules

IPv6 rules are coming soon. The **IPv6 Rules** tab does not accept rules yet.

## Edit or delete a rule

* To **edit**, change any field in the rule row and click **Save** on that row.
* To **delete**, click the delete icon on the rule row. The rule is removed immediately — there is no separate save step.

> **Warning**
>
> System-managed rules cannot be edited or deleted. They have no **Save** or delete controls.

## Example: allow web traffic

To allow HTTP and HTTPS from anywhere, add and save two rules:

| Action | Protocol | Port | Source   |
| ------ | -------- | ---- | -------- |
| accept | TCP      | 80   | Anywhere |
| accept | TCP      | 443  | Anywhere |

## Example: restrict SSH to an office IP

| Action | Protocol | Port | Source                   |
| ------ | -------- | ---- | ------------------------ |
| accept | TCP      | 22   | Custom: `203.0.113.0/24` |

## Troubleshooting

**Cannot edit a rule**
System-managed rules are read-only. You can only edit or delete rules you created.

**Changes not taking effect**
Make sure you clicked **Save** on each new or changed rule row. Unsaved rows are not applied.

**Custom source validation error**
Enter valid CIDR notation (e.g. `10.0.0.0/8`) or a single IP address. At least one CIDR or IP is required when using Custom source.

## Related pages

* [Firewalls overview](/docs/network-security/firewalls)
* [Linked instances](/docs/network-security/firewalls#linked-instances)