Public reachability
A public address does not have to mean an open device.
A useful rule starts with a service requirement: allow HTTPS to this target from these clients. The assignment’s managed firewall carries that intended exposure. An empty managed rule list means block inbound by default in the current model.
This is a network access control, not a separate security appliance or an application inspection service. A port can be reachable while the application behind it remains insecure, misconfigured or unavailable.
The parts of a rule
Be specific about the traffic and its target.
Scroll sideways to inspect the rule fields.
| Field | What it means | Example or limit |
|---|---|---|
| Target | The public assignment being controlled | Device or gateway allocation |
| Protocol | The traffic type | Current rule contract includes TCP, UDP and ICMP |
| Port | Service port for a port-based protocol | TCP 443; ICMP does not use TCP/UDP ports |
| Source | Where incoming traffic may originate | An assessed source range or an explicitly broad audience |
| Action and enabled state | The intended rule behaviour | Allow or block; a disabled rule is not an active allowance |
Rule processing, gateway forwarding and local enforcement
The schema records intent. Exact rule validation, precedence and enforcement must be verified for the serving implementation; this page does not invent an ordered rule-processing contract. Fully open mode is a separate explicit choice, not the managed default.
A device’s own firewall, the gateway’s forwarding configuration and the target listener still matter. A gateway may forward distinct approved public ports to different LAN servers. Opening a public port does not automatically create that mapping or start the service.
Traffic direction
Who can connect in is separate from how you connect out.
Inbound access allows a remote client to start a connection when the firewall permits it. Replies to that connection must use the correct return path through Fibmesh. Unrelated outgoing traffic can remain on the existing ISP path in the inbound-access configuration.
Selected outbound routes eligible destinations through the assigned public source; full tunnel routes eligible internet traffic through Fibmesh. Neither choice should be described as automatically denying incoming traffic. Inbound policy remains an independent decision, and an outbound-only configuration needs explicit inbound denial.
Compare Public IPs traffic modes →Publish has a different exposure boundary: the gateway maps a hostname to a selected HTTP application. An assignment firewall is not automatically a Publish login policy, a private-network membership rule or an Outbound profile control.
Routed infrastructure
A routed range needs its own exposure plan.
Routed Subnets is a separate invitation-led Public IPs service, outside the app MVP. Routing a prefix to your gateway does not establish that every downstream address or service should be reachable. Agree where filtering happens, which addresses and services are permitted, and who manages the gateway and downstream host firewalls.
Routed-prefix filtering and IPv6 control traffic
Do not infer a released per-prefix firewall editor, automatic rule propagation to every host or identical enforcement to a single-address assignment. Confirm the service configuration for IPv4 and IPv6 separately. For IPv6, account for the control traffic required by the deployed network; a blanket “block all ICMP” policy can break normal operation.
Apply & observe
Test the permission you added—and the access you did not.
Before enabling a rule, identify the owner, source, protocol, target and return route. Confirm the application has authentication and appropriate updates. Review any broad source range as an intentional decision.
After the change, compare requested and observed configuration. Test the intended service from an approved source, then from an unapproved source. Test an unrelated port as well. A stored rule or successful API response is not proof that gateway and endpoint enforcement have converged.
When retiring a service, close the exposure and verify it is no longer reachable. Pausing a Public IP preserves its reservation but removes delivery after the change is applied; releasing it gives up the allocation. Those actions have consequences beyond an individual port rule.
Firewall questions
Keep the boundaries clear.
Can I open any port I want?
The intended service allows deliberate control of supported protocol and port rules. Confirm the deployment’s accepted rule syntax, operational restrictions and service terms. “Fully open” does not bypass platform constraints or the target’s own firewall.
Does an allowlisted source make application login unnecessary?
No. Several users may share a NAT or exit address, and a permitted device can be compromised. Use appropriate application authentication and permissions.
Will the firewall inspect web attacks or stop every attack?
No such claim is made. Network rules limit reachability; they do not establish a web application firewall, malware inspection or a DDoS protection service.
