# Server Firewall

Source: https://support.kapsulehost.com/en-nz/cloud-servers-firewall

The server firewall decides which traffic can reach your server. Only the traffic your rules allow gets through, and everything else is dropped. You set it from the server's **Firewall** tab in KPanel, and nothing changes on the server until you click **Apply Rules**.

## Open the Firewall Tab

1. Sign in to [KPanel](https://kpanel.kapsulehost.com).
2. In the sidebar, open the section for your server type, for example **Standard Cores**, then click your server.
3. In the server's menu, click **Firewall**.

The **Firewall** tab is shown when your server supports it. If you do not see it, use a firewall inside the operating system instead, such as `ufw` on Ubuntu.

![The Firewall tab on a server in KPanel](https://support.kapsulehost.com/help/screenshots/cloud-servers-firewall.10dd5127.webp)

## How Rules Work

Each rule allows one kind of traffic:

| Field | What it means |
|---|---|
| **Direction** | **Inbound** (traffic to the server) or **Outbound** (traffic from it) |
| **Protocol** | TCP, UDP or ICMP (ping). ICMP has no port. |
| **Port** | One port, such as `443`, or a range, such as `8000-8100` |
| **Source (IP Ranges)** | Who the rule allows, as IP ranges separated by commas. `0.0.0.0/0, ::/0` means anywhere. |

A server can have up to 50 rules. With no rules, the tab says "No rules yet. Pick a template or add a rule."

## Start from a Template

Three buttons fill the list with a ready-made set of rules, all from anywhere:

| Template | Rules |
|---|---|
| **Web** | SSH (22), HTTP (80), HTTPS (443) and ping |
| **SSH Only** | SSH (22) |
| **Mail** | SSH (22) and the mail ports 25, 465, 587, 143, 993, 110 and 995 |

A template replaces the list on the screen. It does not add to it. Click **Apply Rules** to put it on the server.

## Add or Change Rules

1. Click **Add Rule** for each extra rule, or start from a template.
2. Set the **Direction**, **Protocol**, **Port** and **Source (IP Ranges)**.
3. Click **Remove** to take a rule out of the list.
4. Click **Apply Rules**. KPanel says "Done."

> **Warning:** **Apply Rules** replaces every rule on the server with the list on the screen. Check the whole list before you apply it, not only the rule you changed.

## Allow SSH from Your Office Only

1. Click **SSH Only**.
2. In **Source (IP Ranges)**, replace the value with your office IP, for example `203.0.113.5/32`.
3. Click **Apply Rules**.

Only do this if your office IP never changes, or you may lock yourself out.

> **Important:** Always keep a rule that allows SSH on port 22, or you cannot sign in. If it happens, add the rule back in KPanel. Your firewall is set from KPanel, so you can always fix it there.

Applying **SSH Only** to a web or mail server stops website and mail traffic. That is expected: only SSH is allowed.

Do not open database ports such as 3306 or 5432 to everyone. If another server needs your database, allow only that server's address, or connect them over a private network from **Add-Ons**, then **Private Networks**.

## Firewall Inside the Server

The KPanel firewall and a firewall inside the operating system (such as `ufw` or `firewalld`) both apply. Traffic must pass both. If a port is open here but still unreachable, check the firewall inside the server too.

## Older Servers

Servers ordered before the new catalogue have their firewall on the server's **Management** page, in the **Firewall (UFW)** section. There you type a port, choose **TCP** or **UDP** and **Allow** or **Deny**, then click **Add**. SSH on port 22 is always open on those servers.

## Troubleshooting

**"Check the rules: each needs a port (except ICMP) and valid IP ranges."** A port must be 1 to 65535, a range is written `8000-8100`, and each source must be an IP range such as `203.0.113.5/32`. ICMP rules take no port.

**I applied the rules and now SSH does not connect.** Your SSH rule is missing or does not include your address. Open **Firewall**, add SSH on port 22 back, and click **Apply Rules**.

**A port is open but nothing answers.** Check the program is running and listening on that port, and check the firewall inside the server.

**"Your role can view this server but cannot change it."** Only the Owner and Admin roles can change the firewall. Ask the account owner.

## Related Articles

- [Connecting to Your Server by SSH](https://support.kapsulehost.com/en-nz/cloud-servers-ssh-connect)
- [Reverse DNS](https://support.kapsulehost.com/en-nz/cloud-servers-reverse-dns)
- [Rescue Mode](https://support.kapsulehost.com/en-nz/cloud-servers-rescue)
- [Server Troubleshooting](https://support.kapsulehost.com/en-nz/cloud-servers-troubleshooting)
- [Managed and Unmanaged Servers](https://support.kapsulehost.com/en-nz/cloud-servers-managed-vs-unmanaged)
