Skip to main content

Firewall rules

Firewall in Templass Panel is how you express allow/deny intent on top of default mitigation. You edit rules in the browser; Templass applies them on the scrubbing side.

How to use it

  1. Open Firewall for the service you care about.
  2. Add or edit a rule (protocol, port or range, action, and any source options Panel offers).
  3. Save and wait for Panel to show the rule as accepted or pending.
  4. Test from a host that is not your origin.

Use the field names and options Panel shows.

Provisioning delay

There can be a short delay between Save and enforcement on every path. Avoid create/delete loops on the same rule. If a rule stays pending too long, ask in Discord or email [email protected] with the rule summary and save time.

During a live attack, prefer one clear change over several experimental ones. See Under attack.

Practical tips

  • Allow the ports you actually serve. Request missing listeners via Port requests.
  • Keep deny rules specific so you do not lock yourself out.
  • Prefer keeping management access (SSH, RDP, provider APIs) off the protected prefix when you can.

Firewall works together with routing and plan capacity. An origin IP you publish yourself, or clean traffic above your plan include, still needs the usual routing and billing care.