Configuring Default Firewall Rules

Default firewall rules functionality is applicable only to the CS/VPS Hosting model.

You can specify firewall rules, which will be applied to a virtual server after provisioning by default, to provide security of your customers' virtual servers. The firewall rules are defined per OS template. When a virtual server is created, the firewall rules are copied from OS template to a virtual server. Therefore, any changes like adding, editing, removing, applying/canceling firewall rule affect only the newly created servers, the existing ones are not affected and the rules applied to them earlier are preserved.

By default there are five firewall rules required for Plesk provisioning in the virtual server (they are hidden in PCP to prevent any modifications):

  • Plesk panel rule (TCP port 8443)
  • Plesk updates rule (TCP port 8447)

They will be applied automatically to virtual servers with Plesk.

To create a firewall rule, do the following:

  1. In Operations control panel, go to Services > Cloud Infrastructure > Firewall Rules.
  2. Click Add Firewall Rule.
  3. Specify the name of the firewall rule, allowed protocol, remote port (port on a remote server from which the request/data are sent) and local port (port on your local server which receives request).
  4. Specify what OS template(s) the newly created firewall rule will be applied to by selecting the desired templates in the Existing OS Templates section.

    Note: The newly created firewall rule will affect only new virtual servers based on these OS templates, the existing virtual servers won't be affected.

  5. If the newly created firewall rule is universal and you are going to use it for every newly created OS template, select the Apply this rule to all new OS templates option in the New OS Templates section.
  6. When ready, click Finish.