The Contabo Firewall filters traffic at network level, before it reaches the instance. It runs independently of the guest operating system: rules survive reboots, reinstalls and OS-level misconfiguration. All inbound traffic is blocked from the moment a firewall is activated; the customer decides what is allowed in.
Default policy: all inbound traffic is dropped by a permanent default rule; outbound traffic is unrestricted.
Protocols: TCP, UDP and ICMP.
Sources: any (IPv4 and IPv6), any IPv4, any IPv6, a single IP address (e.g. 203.0.113.10) or a CIDR range (e.g. 203.0.113.0/24); comma-separated lists are converted to tags.
Ports: a single port (22), a comma-separated list (22,80,443) or a range (8000-8100); valid range 0–65535.
Predefined types: common rule types such as SSH and HTTPS can be selected instead of entering ports manually.