Firewall
UpCloud provides robust Layer 3 firewalling, positioned directly before the network interface that connects Cloud Servers to other servers or networks. This ensures that all inbound and outbound traffic is filtered according to your configured rules, enhancing security and control over your cloud environment.
Firewall Types
UpCloud offers two types of firewalls: Public & Utility Network Firewall and SDN Firewall.
| Public & Utility Firewall | SDN Firewall | |
|---|---|---|
| Applies to | Traffic between Cloud Servers and public networks, and the Utility Network | Traffic between Cloud Servers and SDN Private Networks |
| IP versions | IPv4 & IPv6 | IPv4 only (IPv6 not supported on SDN Private Networks) |
| Packet inspection | Stateless | Stateful |
| Operating layer | Network layer (L3) | Network layer (L3) |
Public & Utility Firewall
The Public & Utility Firewall filters traffic between Cloud Servers and the Public network and Utility network.
This firewall supports one ruleset per server, with a maximum of 1000 rules. The ruleset cannot be shared between servers.
As a stateless firewall, users must configure rules to allow both incoming and outgoing traffic explicitly.
SDN Firewall
The SDN Firewall filters traffic between Cloud Servers and SDN Private Networks.
Firewall rules in SDN Firewalls are configured in firewall rulesets. These rulesets function as Security Groups and can be associated with any number of Cloud Servers. Each server can have up to 50 firewall rulesets applied.
The SDN Firewall operates as a stateful firewall, automatically allowing return traffic for established connections.
Enabling and Disabling Firewalls
Both firewalls can be enabled and disabled independently:
- When disabled: All associated traffic is allowed
- When enabled: All traffic is filtered according to configured rules
The SDN Firewall allows enabling and disabling rulesets without removing their association with servers. Changes to ruleset status affect all servers using that ruleset.
Outgoing Email SMTP Block
By default, outbound SMTP port 25 is closed on all new accounts to prevent misuse and accidental open relays. This block appears in the Cloud Server's UpCloud firewall settings and cannot be modified directly.
To request port 25 access:
- Contact our support team
- Provide identity verification and payment method
- Explain your use case and requirements
This verification process helps maintain our network's email delivery reputation.
Limitations
- Public & Utility Firewall: Maximum 1000 rules per server
- SDN Firewall: Maximum 1000 rules per ruleset
- Firewalls are only available for Cloud Servers
- Not supported on other services (Managed Load Balancers, Object Storage, Databases, Network Gateways)
Trial Limitations
During the free trial period, connections are limited to standard server ports. Full access is granted upon trial completion.
Allowed connections:
| Inbound port number | Outbound port number |
|---|---|
| 22 | 53 |
| 80 | 80 |
| 443 | 443 |
| 3389 | 8080 |
| 123 | 123 |
| 33434 - 33534 | 33434 - 33534 |
Pricing
All firewall features are included at no additional cost.
