Managed firewall

Choose which traffic reaches your public address.

Define the source, service and target you intend to expose. Inbound permission and outgoing routing remain separate choices.

Explore Public IP traffic modes →
A rule is a deliberate permission. Illustrative model · no live network changes
Allowed service

The source and service match the intended rule.

Source198.51.100.0/24ProtocolTCPPort443 / HTTPSIntended actionAllow
  1. Approved client rangeDocumentation example: 198.51.100.0/24Incoming TCP 443
  2. Assigned public IPAllow TCP 443 from that rangePermitted request
  3. Your web serviceListener + host firewall + login

The rule permits network reachability. It does not authenticate the person or approve the application’s data access.

This illustrates one isolated allow rule. It does not define rule precedence or certify live enforcement; verify the serving gateway and endpoint.

Other source

The service port is right. The source is not.

Source198.51.100.0/24ProtocolTCPPort443 / HTTPSIntended actionAllow
  1. Different client rangeOutside the intended allowanceIncoming TCP 443
  2. Managed firewallNo matching permissionBlocked
  3. Your serviceRequest blocked in this example

A narrow source allowance can limit exposure when the clients have predictable source addresses.

If a client is behind NAT or an exit, evaluate the source address visible to the service boundary. An allowlisted address is not a replacement for user authentication.

Other port

Opening HTTPS does not open administration.

Source198.51.100.0/24ProtocolTCPPort443 / HTTPSIntended actionAllow
  1. Internet clientRequests TCP 22Incoming TCP 22
  2. Managed firewallNo SSH permissionBlocked
  3. Administration serviceNot exposed by the HTTPS rule

With managed mode and no matching inbound allowance, the unrelated service remains closed in this model.

An empty managed rule list means blocked inbound. Fully open mode is a separate, explicit choice; it does not remove the application or host firewall responsibilities.

Public reachability

A public address does not have to mean an open device.

A useful rule starts with a service requirement: allow HTTPS to this target from these clients. The assignment’s managed firewall carries that intended exposure. An empty managed rule list means block inbound by default in the current model.

This is a network access control, not a separate security appliance or an application inspection service. A port can be reachable while the application behind it remains insecure, misconfigured or unavailable.

The parts of a rule

Be specific about the traffic and its target.

Scroll sideways to inspect the rule fields.

Field What it means Example or limit
Target The public assignment being controlled Device or gateway allocation
Protocol The traffic type Current rule contract includes TCP, UDP and ICMP
Port Service port for a port-based protocol TCP 443; ICMP does not use TCP/UDP ports
Source Where incoming traffic may originate An assessed source range or an explicitly broad audience
Action and enabled state The intended rule behaviour Allow or block; a disabled rule is not an active allowance
Rule processing, gateway forwarding and local enforcement

The schema records intent. Exact rule validation, precedence and enforcement must be verified for the serving implementation; this page does not invent an ordered rule-processing contract. Fully open mode is a separate explicit choice, not the managed default.

A device’s own firewall, the gateway’s forwarding configuration and the target listener still matter. A gateway may forward distinct approved public ports to different LAN servers. Opening a public port does not automatically create that mapping or start the service.

Traffic direction

Who can connect in is separate from how you connect out.

Inbound access allows a remote client to start a connection when the firewall permits it. Replies to that connection must use the correct return path through Fibmesh. Unrelated outgoing traffic can remain on the existing ISP path in the inbound-access configuration.

Selected outbound routes eligible destinations through the assigned public source; full tunnel routes eligible internet traffic through Fibmesh. Neither choice should be described as automatically denying incoming traffic. Inbound policy remains an independent decision, and an outbound-only configuration needs explicit inbound denial.

Compare Public IPs traffic modes →

Publish has a different exposure boundary: the gateway maps a hostname to a selected HTTP application. An assignment firewall is not automatically a Publish login policy, a private-network membership rule or an Outbound profile control.

Routed infrastructure

A routed range needs its own exposure plan.

Routed Subnets is a separate invitation-led Public IPs service, outside the app MVP. Routing a prefix to your gateway does not establish that every downstream address or service should be reachable. Agree where filtering happens, which addresses and services are permitted, and who manages the gateway and downstream host firewalls.

Routed-prefix filtering and IPv6 control traffic

Do not infer a released per-prefix firewall editor, automatic rule propagation to every host or identical enforcement to a single-address assignment. Confirm the service configuration for IPv4 and IPv6 separately. For IPv6, account for the control traffic required by the deployed network; a blanket “block all ICMP” policy can break normal operation.

Understand routed subnet delivery →

Apply & observe

Test the permission you added—and the access you did not.

Before enabling a rule, identify the owner, source, protocol, target and return route. Confirm the application has authentication and appropriate updates. Review any broad source range as an intentional decision.

After the change, compare requested and observed configuration. Test the intended service from an approved source, then from an unapproved source. Test an unrelated port as well. A stored rule or successful API response is not proof that gateway and endpoint enforcement have converged.

When retiring a service, close the exposure and verify it is no longer reachable. Pausing a Public IP preserves its reservation but removes delivery after the change is applied; releasing it gives up the allocation. Those actions have consequences beyond an individual port rule.

Firewall questions

Keep the boundaries clear.

Can I open any port I want?

The intended service allows deliberate control of supported protocol and port rules. Confirm the deployment’s accepted rule syntax, operational restrictions and service terms. “Fully open” does not bypass platform constraints or the target’s own firewall.

Does an allowlisted source make application login unnecessary?

No. Several users may share a NAT or exit address, and a permitted device can be compromised. Use appropriate application authentication and permissions.

Will the firewall inspect web attacks or stop every attack?

No such claim is made. Network rules limit reachability; they do not establish a web application firewall, malware inspection or a DDoS protection service.

See the wider security responsibilities →