Skip to main content
Manage basic firewall rules
Last update:

Manage basic firewall rules

For a basic firewall, you can add new rules, modify existing rules and their order, delete rules.

Add rule

carefully

After adding the first rule for a direction, the base rule is automatically connected: all traffic that is not allowed is prohibited. You cannot delete a base rule.

  1. In Control Panel, go to Servers and colocationBasic Firewall.

  2. Open the firewall page.

  3. Open the tab depending on which traffic you want to add a rule for:

    • for incoming traffic — Incoming traffic;
    • for outgoing traffic — outgoing traffic.
  4. If you have already added or edited rules, view firewall status. Verify that the firewall is displaying APPLIED status. From the firewall menu, click Change Rule List. Click Add Rule.

  5. If you have not added or edited rules, click Add Rule.

  6. Check the direction of the traffic.

  7. Select an action:

    • accept — accept traffic;
    • deny — deny traffic.
  8. Enter Source address — IP addresses from which to accept requests. You can enter an IP address or subnet.

  9. Enter Destination address — IP addresses to which requests can be accepted. You can enter an IP address or subnet.

  10. Enter Source port — the source port from which the request is coming. You can enter a port or a range of ports.

  11. Enter Destination port — the port on which the request will be received. You can enter a port or a range of ports. Traffic to any TCP/UDP port blocked in Selectel by default will be denied even if you specify that port in the rule.

  12. Select the protocol: TCP, UDP, ICMP, IPIP, GRE, ESP, NA.

  13. Optional: enter a description of the rule.

  14. Click Create Rule.

  15. Check the order of the rules, they are executed in order in the list — top to bottom. If necessary change rule order — drag and drop rules.

  16. Press Activate List. When the rules are activated, the firewall will display the APPLIED status. It may take up to 30 seconds to apply the changes. If you don't activate the list, the rules will reset.

Modify rule

  1. In Control Panel, go to Servers and colocationBasic Firewall.

  2. Open the firewall page.

  3. Open the tab depending on which traffic you want to change the rule for:

    • for incoming traffic — Incoming traffic;
    • for outgoing traffic — outgoing traffic.
  4. From the menu of the rule list, click Modify Rule List.

  5. From the rule menu, click Edit Rule.

  6. Change the values of the parameters in the rule.

  7. Click Save Changes.

  8. Press Activate List. When the rules are activated, the firewall will display the APPLIED status. It may take up to 30 seconds to apply the changes. If you do not activate the list, the changes will be reset.

Change the order of the rules

  1. In Control Panel, go to Servers and colocationBasic Firewall.

  2. Open the firewall page.

  3. Open the tab depending on which traffic you want to change the order of the rules for:

    • for incoming traffic — Incoming traffic;
    • for outgoing traffic — outgoing traffic.
  4. From the rules menu, click Modify Rules List.

  5. Drag and drop rules. You can't drag and drop a base rule.

  6. Press Activate List. When the rules are activated, the firewall will display an APPLIED status. It may take up to 30 seconds to apply the changes. If you do not activate the list, the changes will be reset.

Delete rule

carefully

The rule will no longer be in effect — traffic that was allowed by this rule will be denied.

  1. In Control Panel, go to Servers and colocationBasic Firewall.

  2. Open the firewall page.

  3. Open the tab depending on which traffic you want to remove the rule for:

    • for incoming traffic — Incoming traffic;
    • for outgoing traffic — outgoing traffic.
  4. From the menu of the rule list, click Modify Rule List.

  5. From the rule menu, click Delete Rule.

  6. Press Activate List. When the rules are activated, the firewall will display an APPLIED status. It may take up to 30 seconds to apply the changes. If you do not activate the list, the changes will be reset.