Appearance
Create Firewall Groups and Inbound Rules
Firewall groups are reusable inbound-rule sets. You choose one firewall group when provisioning a device; selecting None leaves the device with default-deny inbound traffic.
Rules are allow-only. Traffic is blocked unless it matches a rule, which is evaluated as:
port AND protocol AND (host OR device group OR device groups OR cidr)Creating a Firewall Group
- Navigate to the Firewall Groups page in the dashboard.
- Click Create Firewall Group.
- Enter a Group name (e.g.
web-access). - Add one or more inbound rules, or use Allow all traffic only when that is genuinely appropriate.
- Click Create group.
Inbound Rule Fields
Each inbound rule has the following fields:
- Port:
0,any, a single value (80), a range (200-901), orfragment. - Protocol:
TCP,UDP,ICMP, orANY. Port is ignored forICMP. - Host:
anyor a specific source-device name. - Device Group: require one certificate group on the source device.
- Device Groups (comma separated): an AND match; the source device must have every listed group. This field cannot be combined with Device Group.
- CIDR: remote network range. Use
0.0.0.0/0for any IPv4,::/0for any IPv6, oranyfor both families.
Each rule must include at least one selector: host, device group, device groups, or CIDR.
Do not combine Host any with a device-group selector: any already matches every source host. When a device is provisioned with a firewall group, the certificate groups referenced by that firewall group's rules are also assigned to that device. This lets other devices' inbound rules select it as a source.
Rules can be reordered with the up/down controls and removed with the delete button. Editing a firewall group changes the saved template; already-issued device certificates and configurations are not silently reissued. Reprovision a device when you need it to use changed certificate groups or firewall rules.
WARNING
Firewall rules cannot restore connectivity to a device created with Isolate from other devices. Peer isolation changes which certificate authorities the device trusts; firewall evaluation happens only after that trust relationship exists.