Network security
Ports
Blocked ports
To secure Servercore infrastructure from malicious network activity, we restrict access to certain TCP/UDP ports. On edge routers at the edge of the Servercore Internet network, both incoming and outgoing traffic is blocked. There is an exception for TCP port 25 — only outgoing traffic is blocked to limit the sending of potentially malicious email. The list of blocked ports is available in the instruction Blocked ports and Internet resources.
Ports that are most often opened
Firewalling
To protect your system, limit incoming and outgoing traffic. Define a list of required network services and for each of your servers, allow connections only to network ports that are associated with those services. If necessary, restrict the source address of the connection. All connections that are not explicitly allowed should be blocked.
Network security for private subnets and public IP addresses can be provided by:
- Cloud Firewall — a stateful firewall for cloud servers. You can manage it in the control panel, via OpenStack CLI;
- Basic Firewall — a stateless firewall for dedicated servers. It can only be managed in the control panel.
Security groups in the cloud platform
Using security groups you can configure filtering rules for all traffic passing through a cloud server port.
Network Attack Detection and Prevention (IPS)
To detect and prevent network attacks, we recommend using specialized solutions — Intrusion Prevention System (IPS).
Among the free tools that perform IPS functions, the most popular and functional are:
As a Host-based Intrusion Detection System (HIDS), we recommend using Wazuh.
Server-level network protection
You can also protect network connections at the specific server level. On Linux servers, we recommend using:
- Uncomplicated Firewall (UFW) — a tool for firewall configuration. It is designed for the Ubuntu distribution but is also available for other distributions, such as Debian;
- firewalld — a firewall management system installed by default in distributions based on Red Hat Enterprise Linux, such as Fedora, CentOS, Alma Linux, Rocky Linux, and Oracle Linux. Learn more about configuration in the firewalld documentation and see configuration examples in the Fedora documentation.
When configuring a firewall, keep in mind that some ports originally intended for specific services can be used by attackers for hacking. For example, 21/TCP (FTP), 22/TCP (SSH), 23/TCP (Telnet), and 3389/TCP (RDP) are dangerous as they are often subjected to brute-force attacks and vulnerability exploitation. A full list of such ports can be found in the table Ports that are most often left open.
Network access to a Managed Database cluster
In Managed Databases, you can configure network access to the cluster. Users only have access to the cluster itself — there is no access to the cluster nodes as they are located on the Servercore side. By default, in clusters with a public subnet, connection is allowed for all addresses if a login and password are provided. For a cluster in a private subnet, the connection is allowed from the cluster subnet and from those subnets connected to the cluster subnet via a cloud router. You can limit the list of addresses from which access to the database cluster is allowed. More information is available in the instructions for PostgreSQL, PostgreSQL for 1C, PostgreSQL TimescaleDB, MySQL semi-sync, MySQL sync, Redis and Kafka.
DDoS protection
Servercore provides free infrastructure protection against DDoS attacks at the network and transport layers (L3-L4) — see the Servercore Protection instruction for details. Information about blocked attacks, network blocks, and blocked IP addresses is available in the control panel in the Products → Network Incidents. More details about the information you can track are provided in the Network Incidents.
Web application security
To protect web applications at the application layer (L7), we recommend using specialized solutions — Web Application Firewall (WAF).
Among the free tools that perform WAF functions, the most popular and functional are: