Create a cloud firewall
A cloud firewall has a basic property: all incoming and outgoing traffic that is not explicitly allowed is denied. If you create a firewall without any rules and assign it to a cloud router port, all traffic in the router's subnet will be denied. Active sessions on the router will be interrupted after the firewall is created.
Control panel
OpenStack CLI
Terraform
-
In the Control panel, in the top menu, click Products and select Cloud Servers.
-
Go to Firewalls.
-
Click Create firewall.
-
Select the location where the firewall will be created.
-
Optional: select a private subnet with a cloud router for which you want to configure traffic filtering. The firewall is assigned to the cloud router port in this private subnet.
Assigning a firewall to a router port is available after the firewall is created.
-
Select the traffic direction:
Incoming traffic
Outgoing traffic
-
If the rule templates for inbound traffic suit your needs, click the rule. The protocol, source, source port, traffic destination, and destination port fields will be filled in automatically. Proceed to step 15.
-
If there is no suitable template, add your own rule for inbound traffic. Click Add inbound traffic rule.
-
Select an action:
- Allow — allow traffic;
- Deny — deny traffic.
-
Select a protocol: ICMP, TCP, UDP, or all protocols (Any).
-
Enter the traffic source (Source) — an IP address, a subnet, or all addresses (Any).
-
Enter the source port (Src. port) — one port, a range of ports, or all ports (Any).
-
Enter the traffic destination (Destination) — an IP address, a subnet, or all addresses (Any). If you specify a subnet, the rule will apply to all devices in the subnet.
-
Enter the destination port (Dst. port) — one port, a range of ports, or all ports (Any).
Traffic to any TCP/UDP port blocked in Servercore by default will be denied, even if you specify this port in the rule.
-
Enter a name for the rule or leave the automatically generated name.
-
Optional: enter a comment for the rule.
-
Click Add. After creating the firewall, you can edit the rule.
- Check the order of the rules; they are executed in order from top to bottom. If necessary, change the order by dragging the rules. After creating the firewall, you can change the rule order.
- Optional: to add another rule to the firewall, proceed to step 6. You can add up to 100 rules for each traffic direction.
- Enter a name for the firewall or leave the automatically generated name.
- Optional: enter a comment for the firewall.
- Click Create firewall.