Firewall basics in Portal
Kort antwoord
The Portal firewall is a managed gateway that gives internal networks internet access without assigning a public IP to every VPS. Create one under Portal under Firewall → Create Firewall, then manage port forwarding under its NAT Rules tab and outbound access under Firewall Rules.
This is a portal-level firewall that sits in front of your network, not a firewall running inside an operating system. One firewall covers one region or location. If you're looking for OS-level firewall tools instead, see the related articles below.
Create a firewall
Go to Firewall
In Portal, open Firewall and select Create Firewall.
Select a region
An internet pool is assigned automatically for that region.
Attach internal networks (optional)
Attach the internal networks you want this firewall to protect.
Wait for the firewall to go ACTIVE
The Overview tab is available straight away. The other tabs (NAT Rules, Firewall Rules, Performance, Logs, Settings, Properties) only become usable once the firewall reaches ACTIVE status.
Create Firewall
Firewall → Create Firewall
Create Firewall
Other tabs stay disabled until the firewall reaches ACTIVE status.
Outbound traffic
The Firewall Rules tab controls what traffic VPS instances on your internal networks can send out to the internet through the gateway. Open the tab to see the default policy and the rules already in place before you add your own.
If a service behind the firewall needs to reach something outbound that the existing rules do not cover (a custom API, an SMTP relay, a package mirror on an unusual port), add a rule for it here.
Set up port forwarding
To let inbound traffic reach a specific VPS behind the firewall, use the NAT Rules tab. A port forward maps a port on the firewall's own public address to a port on one VPS behind it, so you decide which services are reachable from the internet and on which ports.
For example, a forward from TCP port 8080 on the firewall to port 80 on a VPS at 10.0.0.5 means traffic arriving at the firewall's public IP on port 8080 reaches that VPS on port 80. Work out the protocol, the external port, the internal address and the internal port before you start, then fill in the form on the tab.
Check the logs
The Logs tab shows security logs, fetched live from the gateway, covering the last 2 hours. Use it to confirm whether traffic is actually reaching a rule you've configured, or being dropped before it gets there.