Firewall

Create reusable firewall profiles, add inbound and outbound rules, attach them to public IPs, and save changes. A full portal tutorial for securing Kloude endpoints.

Firewall

A firewall profile is a reusable set of allow/deny rules you attach to public IP resources. Rules say which traffic may enter or leave (TCP, UDP, or ICMP), so only the ports your app needs stay open on private networking and public endpoints.

Firewalls live under Networking → Firewalls. This page is the deep tutorial for profiles and rules; see Networking for VPC and public IP context.

What you see in the panel

The profile list shows name, status (for example Inactive), rule count, connected resources, and created time. The primary action is + Create new firewall profile. Search by profile name or id, clear sorting or filters, and refresh.

Inside a profile you add rules with + Add rule, edit title, source (All or a CIDR), protocol, port, and an optional port range, then Save changes. The default profile can be edited but not deleted.

Connected resources lets you attach the profile to available public IPs (for example type vpc_public_ip) before traffic policies take effect.

When to use it

Use firewall profiles to limit access to a load balancer VIP or node public IP, open only the ports your app needs (for example 80/443 or one custom TCP port), separate staging from production with different profiles, and harden services after you create a VPC.

Components

A profile is the named rule set under Networking → Firewalls. Rules define direction or source, protocol, and ports as shown in the portal. Attachment assigns the profile to the public IPs that should enforce it.

Tutorial: profile, rules, attach, save

1

Open Firewalls

Go to Networking, then select Firewalls.

2

Create a profile

Click + Create new firewall profile and give it a clear name (for example web-prod). Or open an existing profile such as Default if you only need to tighten rules.

3

Add least-privilege rules

Click + Add rule. Prefer specific ports over ALL for TCP/UDP. Name rules so teammates understand intent (for example Allow HTTPS).

4

Attach to public IPs

Open Connected resources, select the public IPs that should use this profile, then confirm.

5

Save and verify

Click Save changes. From a client, verify only intended ports respond. Re-check after every new LoadBalancer Service.

Default profile:

The default firewall profile can have its rules edited, but the profile itself cannot be deleted. Create custom profiles for environment-specific policies.