Resources

Firewall

UpCloud provides robust Layer 3 firewalling, positioned directly before the network interface that connects Cloud Servers to other servers or networks. This ensures that all inbound and outbound traffic is filtered according to your configured rules, enhancing security and control over your cloud environment.

Firewall Types

UpCloud offers two types of firewalls: Public & Utility Network Firewall and SDN Firewall.

Public & Utility FirewallSDN Firewall
Applies toTraffic between Cloud Servers and public networks, and the Utility NetworkTraffic between Cloud Servers and SDN Private Networks
IP versionsIPv4 & IPv6IPv4 only (IPv6 not supported on SDN Private Networks)
Packet inspectionStatelessStateful
Operating layerNetwork layer (L3)Network layer (L3)

Public & Utility Firewall

The Public & Utility Firewall filters traffic between Cloud Servers and the Public network and Utility network.

This firewall supports one ruleset per server, with a maximum of 1000 rules. The ruleset cannot be shared between servers.

As a stateless firewall, users must configure rules to allow both incoming and outgoing traffic explicitly.

SDN Firewall

The SDN Firewall filters traffic between Cloud Servers and SDN Private Networks.

Firewall rules in SDN Firewalls are configured in firewall rulesets. These rulesets function as Security Groups and can be associated with any number of Cloud Servers. Each server can have up to 50 firewall rulesets applied.

The SDN Firewall operates as a stateful firewall, automatically allowing return traffic for established connections.

Enabling and Disabling Firewalls

Both firewalls can be enabled and disabled independently:

  • When disabled: All associated traffic is allowed
  • When enabled: All traffic is filtered according to configured rules

The SDN Firewall allows enabling and disabling rulesets without removing their association with servers. Changes to ruleset status affect all servers using that ruleset.

Outgoing Email SMTP Block

By default, outbound SMTP port 25 is closed on all new accounts to prevent misuse and accidental open relays. This block appears in the Cloud Server's UpCloud firewall settings and cannot be modified directly.

To request port 25 access:

  1. Contact our support team
  2. Provide identity verification and payment method
  3. Explain your use case and requirements

This verification process helps maintain our network's email delivery reputation.

Limitations

  • Public & Utility Firewall: Maximum 1000 rules per server
  • SDN Firewall: Maximum 1000 rules per ruleset
  • Firewalls are only available for Cloud Servers
  • Not supported on other services (Managed Load Balancers, Object Storage, Databases, Network Gateways)

Trial Limitations

During the free trial period, connections are limited to standard server ports. Full access is granted upon trial completion.

Allowed connections:

Inbound port numberOutbound port number
2253
8080
443443
33898080
123123
33434 - 3353433434 - 33534

Pricing

All firewall features are included at no additional cost.

Can't find what you're looking for?

For more help you can contact our awesome 24/7 support team