> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.ibee.ai/docs/network-security/firewalls/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.ai/_mcp/server. # Firewall as a Service > Create reusable firewall groups with inbound rules to control traffic to your Cloud VMs and GPU VMs. IBEE Solutions Firewalls let you define inbound traffic rules and attach them to your VMs. Each firewall group contains a set of rules that control which traffic is allowed or dropped before it reaches your server. Firewalls are managed from the portal sidebar under **Network**. ## How firewalls work * A **firewall group** is a named collection of rules. Each organization has a default firewall group. * Rules are evaluated in order. Each rule specifies a protocol, port range, source, and action (accept or drop). * Firewall groups can be attached to multiple VMs. A VM can have one firewall group at a time. * Rules support both **IPv4** and **IPv6** traffic, managed in separate tabs. ## Firewall group structure Each firewall group has three tabs: | Tab | Contents | | ------------- | --------------------------------------------- | | **IPv4** | Inbound rules for IPv4 traffic | | **IPv6** | Inbound rules for IPv6 traffic | | **Instances** | VMs currently attached to this firewall group | ## Rule components Each rule has the following fields: | Field | Options | | ------------ | -------------------------------------------------------- | | **Action** | **Accept** (allow traffic) or **Drop** (block traffic) | | **Protocol** | TCP, UDP, ICMP, or Any | | **Port** | Port number, range (e.g. `8000-9000`), or all ports | | **Source** | **Anywhere** (`0.0.0.0/0`) or **Custom** CIDR/IP address | ## Common application ports The portal offers quick-pick buttons for common services: | Application | Protocol | Port | | ----------- | -------- | ---- | | SSH | TCP | 22 | | HTTP | TCP | 80 | | HTTPS | TCP | 443 | | MySQL | TCP | 3306 | | PostgreSQL | TCP | 5432 | | DNS | UDP | 53 | | MS RDP | TCP | 3389 | ## System-managed rules Some rules are system-managed and cannot be edited or deleted. These are marked in the rule list and ensure essential connectivity (e.g., DHCP, metadata service). ## Default firewall group Each organization has a default firewall group. New VMs are automatically associated with it unless you specify a different group during deployment. ## Linked instances The **Instances** tab shows all VMs attached to the firewall group, including: * Instance name * Status (running, stopped, etc.) * IP addresses * OS label ## Best practices * Start with a **deny-all** posture and explicitly allow only the ports you need. * Use **Custom** source CIDRs to restrict access to known IP ranges instead of **Anywhere**. * Keep SSH (port 22) access restricted to your office or VPN CIDR. * Review attached instances periodically to ensure the right VMs are protected. ## Related pages * [Create firewall rules](/docs/network-security/firewalls/create-firewall-rules) * [Attach firewalls to resources](/docs/network-security/firewalls/attach-firewalls-to-resources) * [Inbound rules](/docs/network-security/firewalls/inbound-rules) * [Create a VM](/docs/infrastructure/cloud-vms/create-a-vm) > Create reusable firewall groups with inbound rules to control traffic to your Cloud VMs and GPU VMs. ## Docs - [Create firewall rules](https://docs.ibee.ai/docs/network-security/firewalls/create-firewall-rules.md): Add inbound firewall rules to control which traffic reaches your IBEE Solutions VMs.