Skip to content
Odinex Cloud
Concepts

Firewalls

Stateful rules for inbound and outbound traffic, applied to servers directly or by label.

A firewall is a set of rules that you apply to servers. Firewalls are stateful: replies to allowed connections are always let through.

A server without a firewall accepts all inbound traffic. Apply a firewall to every server that does not need to be fully open.

How rules work

  • Inbound (direction: in): everything is blocked except what a rule allows.
  • Outbound (direction: out): if the firewall has no outbound rules, all outbound traffic is allowed. As soon as it has one, only what the outbound rules allow is let out.
  • If several firewalls apply to a server, the server gets the rules of all of them combined. Because rules only ever allow traffic, a firewall without outbound rules lets all outbound traffic out, even if another firewall on the same server has outbound rules.

Each rule has:

FieldValues
directionin or out
protocoltcp, udp, icmp, esp or gre
portFor tcp and udp only, and required there: a port ("443") or a range ("1000-2000")
source_ipsInbound rules: the CIDRs allowed to connect, e.g. 0.0.0.0/0 and ::/0 for everyone
destination_ipsOutbound rules: the CIDRs the server may connect to
descriptionOptional text

A firewall can have up to 50 rules. Setting the rules replaces the whole list.

rules.json
[
  { "direction": "in", "protocol": "tcp", "port": "22", "source_ips": ["198.51.100.0/24"], "description": "SSH from the office" },
  { "direction": "in", "protocol": "tcp", "port": "443", "source_ips": ["0.0.0.0/0", "::/0"] },
  { "direction": "in", "protocol": "icmp", "source_ips": ["0.0.0.0/0", "::/0"] }
]
odx firewall create --name web --rules-file rules.json
odx firewall add-rule --direction in --protocol tcp --port 80 --source-ips 0.0.0.0/0,::/0 web

Applying a firewall

A firewall is applied to resources in one of two ways (apply_to_resources):

  • server: one specific server.
  • label_selector: every server in the project whose labels match the selector, for example role=web. Servers you create, relabel or delete later are picked up automatically; the firewall's applied_to_servers shows which servers currently match.
odx firewall apply-to-resource --type label_selector --label-selector role=web web
odx firewall apply-to-resource --type server --server db-1 web

You can also pass up to five firewalls when creating a server, so it is protected from its first boot.

A firewall that is still applied to resources has to be removed from them before you can delete it.

On this page