Product Description Basic Firewall
The Basic Firewall is a free stateless firewall (a firewall without state tracking). It analyzes and filters all incoming and outgoing IPv4 traffic according to the added filtering rules.
You can create a basic firewall only for a public dedicated subnet (VLAN) of a dedicated server . You can view all created firewalls in the Control panel: in the top menu, click Products → Dedicated Servers → Basic Firewall.
The basic firewall does not protect the network from DDoS attacks. For this, Servercore has blocked certain TCP/UDP ports by default and enabled Servercore Protection.
How it works
A basic firewall is deployed on the access layer router and is not configured by default.
To restrict traffic flow, add rules and activate the rule list. Rules are executed sequentially, in the order they appear in the list. When you add the first rule, the default rule is automatically applied: all traffic not permitted by the rules is blocked. The default rule cannot be deleted.
The firewall analyzes incoming and outgoing traffic based on the parameter values in the rules:
- protocol — supported protocols are TCP, UDP, ICMP, IPIP, GRE, ESP, AH;
- the port or range of ports of the traffic source (source port);
- the port or range of ports of the traffic destination (destination port);
- IP address or subnet of the traffic source (source address);
- IP address or subnet of the traffic destination (destination address).
The Basic Firewall processes each packet in isolation—it does not remember established connections or track the state of TCP sessions. When analyzing traffic, the firewall only checks the header of each packet for compliance with the rules:
- outgoing packets are checked only against outgoing rules;
- incoming packets are checked only against incoming rules, even if an incoming packet is a response to an allowed outgoing request.
For example, a rule that allows incoming SSH connections on port 22 has been added to the basic firewall. In order for the server to send responses to SSH requests, you need to add an outbound traffic rule: either allow all outbound traffic or allow outbound packets only from port 22. For more details on basic firewall rule configuration, see the Basic firewall rule configuration examples subsection of the Manage basic firewall rules guide.
Cost
A basic firewall is provided free of charge.
Limitations
You can set up to 15 rules for each traffic direction.
For each rule, you can add up to 30 IP addresses or subnets for the traffic source (source address) and traffic destination (destination address).
You can create only one firewall for a single VLAN.