Virtual servers
The firewall
Choose which ports reach your virtual server, apply a tested preset, write your own rules, and get back in if you lock yourself out.
Last reviewed 2026-10-04
The firewall decides which traffic reaches your server. It runs outside your operating system, so a rule you set here holds even if something inside the server is misconfigured. Changes take effect within seconds and never restart anything.
Open your server and click Security.
What you start with
Every new virtual server is created with the firewall already on.
- A Linux server starts on the Secure baseline preset: port 22 and ping are allowed, everything else is refused.
- A Windows server starts on the Windows server preset: port 3389 and ping are allowed, everything else is refused.
So if you are opening a website, a game port or a database port, you have to allow it here first.
The default and the switch
The Firewall card has a switch at the top. Turn it off and the firewall stops filtering inbound traffic entirely.
Under it is the sentence Anything not matched is followed by three choices:
- dropped, the default. The traffic is thrown away with no reply, so a scanner sees nothing at all.
- rejected. The sender is told the port is closed. Slightly friendlier, slightly more informative to an attacker.
- allowed. Everything reaches the server unless a rule says otherwise. Only sensible if you run your own firewall inside the server.
Presets
A preset replaces every rule in the list with a tested set for one kind of server. Your attack protection settings are not touched.
| Preset | What it opens |
|---|---|
| Secure baseline | Remote administration and ping only. The right starting point. |
| Web server | Remote administration, HTTP on 80, HTTPS on 443 over both TCP and UDP, and ping. |
| Game server | Remote administration plus the port ranges common game servers use, on TCP and UDP. Narrow it down afterwards. |
| Windows server | Remote Desktop and ping only. |
| Windows web server | Remote Desktop, HTTP, HTTPS and ping. |
| Mail server | Remote administration plus SMTP, submission, IMAP and POP3 over TLS. |
| No filtering | Every port reachable. The firewall stops filtering inbound traffic. |
| Fully closed | Nothing reaches the server at all, not even remote administration. |
Click a preset, read the confirmation and click Apply preset.
Fully closed is the one to be careful with. It closes the port you use to reach the server, so you have to type CLOSE EVERYTHING to confirm it, and afterwards the only way in is the console in your browser.
On a Windows server, any rule for port 22 in a preset is rewritten to 3389 for you.
Writing your own rule
Click Add a rule. The important fields are at the top.
| Field | What to put |
|---|---|
| Direction | Inbound for traffic arriving from the internet. That is almost always what you want. |
| Verdict | Allow, Drop or Reject. |
| Protocol | TCP, UDP, ICMP or Any. Pick Any for a rule that is not about ports. |
| Port | One port such as 443, a range such as 7000:7010, or a comma separated list. |
| From address | Leave it empty for anywhere, or lock it to one address or network such as 203.0.113.0/24. |
| Note | So you remember what the rule is for. |
Behind More options are the rest: a source port, a destination address, which network adapter to match, an ICMP type, and whether to write a line to the server log each time the rule matches.
How rules are read
Rules are checked from the top down and the first match decides. A new rule goes to the top of the list. Anything that matches nothing falls through to the default.
So if you want to allow one address and refuse the rest, the allow rule has to sit above the drop rule. Use Move up and Move down on each row to get the order right.
Editing and removing
Each row has a pencil to edit it, a button to Disable or Enable it without deleting it, and a bin to delete it. Deleting asks you to confirm first.
A rule that uses a built in macro cannot be edited. Delete it and add a plain rule instead.
Not enforced yet
If you see a warning saying your rules are saved but not being enforced, the firewall is not attached to the server's network adapter and every port is currently reachable. Click Start enforcing these rules. It takes effect in seconds and does not restart the server.
Locking yourself out
The panel tries hard to stop you. If no rule allows the port you use to reach the server, port 22 on Linux or 3389 on Windows, you get a warning, and turning the firewall on in that state is refused outright until you add a rule or apply a preset.
If you manage it anyway, you are not stuck. Open the console in your browser, which does not go through the firewall, and fix the rules from the panel or from inside the server.
The safer habit is to put your own address on the always allowed list before you start changing rules. Anything on that list gets through before the rules are read.
A worked example: a website
You have a fresh Linux server and you want to serve a site.
- Open Security.
- Click Web server in the presets and apply it. Ports 22, 80 and 443 are now open.
- Install your web server inside the machine as normal.
That is it. If you later add a service on another port, say a database on 5432 that only your own office should reach:
- Click Add a rule.
- Direction Inbound, verdict Allow, protocol TCP, port
5432. - In From address, put your office address, for example
203.0.113.0/24. - Add a note so you know what it is, then save it.
Leaving From address empty would open your database to the whole internet. Fill it in.