Network security
Ports
Blocked ports
To protect the Servercore infrastructure from malicious network activity, we restrict access to certain TCP/UDP ports. Inbound and outbound traffic is blocked on border routers at the perimeter of the Servercore Internet network. An exception applies to TCP port 25 — only outbound traffic is blocked to limit the sending of potentially malicious mail. For a list of blocked ports, see the Blocked ports and Internet resources guide.
Ports that are most often opened
Firewalling
To protect your system, limit incoming and outgoing traffic. Define a list of required network services and for each of your servers, allow connections only to network ports that are associated with those services. If necessary, restrict the source address of the connection. All connections that are not explicitly allowed should be blocked.
Network security for private subnets and public IP addresses can be provided by:
- Cloud Firewall — a stateful firewall for cloud servers. You can manage it in the control panel, via OpenStack CLI;
- basic firewall — a stateless firewall for dedicated servers. You can only work with it in the control panel.
Security groups in the cloud platform
Using security groups you can configure filtering rules for all traffic passing through a cloud server port.
Network Attack Detection and Prevention (IPS)
To detect and prevent network attacks, we recommend using specialized solutions — Intrusion Prevention System (IPS).
Among the free tools that perform IPS functions, the most popular and functional are:
As a host-based intrusion detection system (HIDS), we recommend using Wazuh.
Server-level network protection
You can also protect network connections at the individual server level. On Linux servers, we recommend using:
- Uncomplicated Firewall (UFW) — a firewall configuration tool. It was developed for the Ubuntu distribution, but is also available for other distributions, such as Debian;
- firewalld is a firewall management tool installed by default in distributions based on Red Hat Enterprise Linux, such as Fedora, CentOS, Alma Linux, Rocky Linux, and Oracle Linux. Learn more about configuration in the firewalld documentation and configuration examples in the Fedora documentation.
When configuring a firewall, keep in mind that some ports originally intended for specific services can be exploited by attackers. For example, 21/TCP (FTP), 22/TCP (SSH), 23/TCP (Telnet), and 3389/TCP (RDP) are dangerous because they are frequently targeted by brute-force attacks and vulnerability exploitation. You can view the full list of such ports in the Ports that are opened most often table.
Network access to a Managed Database cluster
In Managed Databases, you can configure network access to a cluster. Users can only access the cluster itself — there is no access to the cluster nodes, as they are located on the Servercore side. By default, in clusters with a public subnet, connections are allowed for all addresses if a login and password are provided. For a cluster in a private subnet, connections are allowed from the cluster subnet and from subnets connected to the cluster subnet via a cloud router. You can restrict the list of addresses from which access to the database cluster is allowed. Learn more in the instructions for PostgreSQL, PostgreSQL for 1C, PostgreSQL TimescaleDB, PostgreSQL PGVector, MySQL semi-sync, MySQL sync, Redis, and Kafka.
DDoS protection
Servercore provides free infrastructure protection against DDoS attacks at the network and transport layers (L3-L4) — learn more in the Servercore protection guide. Information about blocked attacks, network blocks, and blocked IP addresses can be viewed in the control panel under Products → Network incidents. For more information on what you can monitor, see Network incidents.
Web application security
To protect web applications at the application layer (L7), we recommend using specialized solutions — Web Application Firewall (WAF).
Among the free tools that perform WAF functions, the most popular and functional are: