Skip to main content

Create a cloud firewall

warning

A cloud firewall has a basic property: all incoming and outgoing traffic that is not explicitly allowed is denied. If you create a firewall without any rules and assign it to a cloud router port, all traffic in the router's subnet will be denied. Active sessions on the router will be interrupted after the firewall is created.

  1. In the Control panel, on the top menu, click Products and select Cloud Servers.

  2. Go to the Firewalls section.

  3. Click Create firewall.

  4. Select the location where the firewall will be created.

  5. Optional: select a private subnet with a cloud router for which you want to configure traffic filtering. The firewall is assigned to the cloud router port in this private subnet.

    You can assign a firewall to a router port after the firewall has been created.

  6. Select the traffic direction:

  1. If rules templates for incoming traffic work for you, click the rule. The protocol, source, source port, destination, and destination port fields will be filled in automatically. Proceed to step 15.

  2. If no suitable template is available, add a custom rule for incoming traffic. Click Add incoming traffic rule.

  3. Select an action:

    • Allow — allow traffic;
    • Deny — deny traffic.
  4. Select a protocol: ICMP, TCP, UDP, or all protocols (Any).

  5. Enter the traffic source (Source) — an IP address, a subnet, or all addresses (Any).

  6. Enter the source port (Src. port) — one port, a range of ports, or all ports (Any).

  7. Enter the traffic destination (Destination) — an IP address, a subnet, or all addresses (Any). If you specify a subnet, the rule will apply to all devices in the subnet.

  8. Enter the destination port (Dst. port) — one port, a range of ports, or all ports (Any).

    Traffic to any TCP/UDP port blocked in Selectel by default will be denied, even if you specify this port in the rule.

  9. Enter a name for the rule or leave the automatically generated name.

  10. Optional: enter a comment for the rule.

  11. Click Add. After creating the firewall, you can edit the rule.

  1. Check the rule order, they are executed in order in the list — top to bottom. If necessary, change the order — drag the rules. After creating the firewall, you can change the rule order.
  2. Optional: to add another rule to the firewall, proceed to step 6. You can add up to 100 rules for each traffic direction.
  3. Enter a name for the firewall or leave the automatically generated name.
  4. Optional: enter a comment for the firewall.
  5. Click Create firewall.