> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.ibee.co.in/docs/network-security/firewalls/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/_mcp/server. # Firewall as a Service > Create reusable firewall groups with inbound rules to control traffic to your Cloud VMs and GPU VMs. IBEE Solutions Firewalls let you define inbound traffic rules and attach them to your VMs. Each firewall group contains a set of rules that control which traffic is allowed or dropped before it reaches your server. Firewalls are managed from the portal sidebar under **Network & Security**. ## How firewalls work * A **firewall group** is a named collection of inbound rules. * Each rule specifies an action (accept or drop), a protocol, a port or port range, and a source. * A firewall group can be attached to multiple VMs. A VM is in one firewall group at a time. * New VMs are protected by a platform default firewall group. Attaching a VM to one of your firewall groups replaces the default for that VM; detaching it restores the default. ## Firewall group structure Select a firewall group to open it. It has three tabs: | Tab | Contents | | -------------------- | -------------------------------------------------------------------------- | | **IPv4 Rules** | Inbound rules for IPv4 traffic | | **IPv6 Rules** | Coming soon — IPv6 rules can't be added yet | | **Linked Instances** | VMs attached to this firewall group, and controls to attach or detach them | ## Rule components Each rule has the following fields: | Field | Options | | -------------- | ------------------------------------------------------------------------------------ | | **Action** | **accept** (allow traffic) or **drop** (block traffic) | | **Protocol** | Any, TCP, UDP, or ICMP | | **Port / App** | A port number, a range (e.g. `8000-9000`), or a common application; TCP and UDP only | | **Source** | **Anywhere** (`0.0.0.0/0`) or **Custom** CIDR/IP addresses | | **Notes** | Optional note describing the rule | ## Common application ports The **Port / App** picker offers common services: | Application | Protocol | Port | | ----------- | -------- | ---- | | SSH | TCP | 22 | | HTTP | TCP | 80 | | HTTPS | TCP | 443 | | MySQL | TCP | 3306 | | PostgreSQL | TCP | 5432 | | DNS (UDP) | UDP | 53 | | MS RDP | TCP | 3389 | ## System-managed rules Every new firewall group includes system-managed rules: all outbound traffic is allowed, and a final rule drops any inbound traffic that your rules don't accept. System-managed rules have no **Save** or delete controls and cannot be edited or deleted. The firewall page lists inbound rules only. ## Manage firewall groups * **Create** — click **Create Firewall Group**, enter a **Group name** (e.g. `web-tier`), and click **Create Group**. * **Delete** — open the group's menu in the list, click **Delete**, and confirm. Deleting a firewall group cannot be undone. * **Copy ID** — the group's menu also copies the firewall group ID for use with the API. ## Linked instances The **Linked Instances** tab lists the VMs attached to the firewall group with their server name, public IP, status, and attach time. * **Attach** — search for an active instance and click **Attach**. If the VM is already in another firewall group, it moves to this one. * **Detach** — click **Detach** on the instance's row. The VM returns to the platform default firewall group. ## Best practices * Allow only the ports you need — inbound traffic that no rule accepts is dropped. * Use **Custom** source CIDRs to restrict access to known IP ranges instead of **Anywhere**. * Keep SSH (port 22) access restricted to your office or VPN CIDR. * Review linked instances periodically to ensure the right VMs are protected. ## Related pages * [Create firewall rules](/docs/network-security/firewalls/create-firewall-rules) * [VPC](/docs/network-security/vpc-and-ip-management) * [Create a VM](/docs/infrastructure/cloud-vms/create-a-vm) > Create reusable firewall groups with inbound rules to control traffic to your Cloud VMs and GPU VMs. ## Docs - [Create firewall rules](https://docs.ibee.co.in/docs/network-security/firewalls/create-firewall-rules.md): Add inbound firewall rules to control which traffic reaches your IBEE Solutions VMs.