Skip to content

Out new: Firewall for netcup vServer - additional security layer at no extra cost

Firewall-Schutzschild vor Server-Layern als Symbol für zusätzliche Sicherheitsebene.

A new functionality is now available for all netcup vServers from Generation 12 onwards (VPS x86, VPS ARM, Root server, vGPU server) in the Server Control Panel (SCP).

 

The firewall allows you to control the incoming and outgoing traffic of your servers in a targeted manner. This gives you additional protection at network level to block unwanted traffic from your servers at netcup and enables you to gain full control over accessible services.

 

Use of the firewall is free of charge and is available immediately for all new and existing vServer products at netcup.

What does the new firewall offer?

The stateful firewall allows you to granularly control the incoming and outgoing network traffic of your vServer. You can define your own rules both via the SCP and via the API to specifically allow or block certain protocols, ports or IP ranges. This ensures that only desired connections are allowed and that internal services are not unintentionally accessible to the public.

 

Key benefits:

  • Additional layer of security at no extra cost
  • Rule-based control over incoming and outgoing traffic
  • Filtering directly at network level before requests reach the server itself
  • Enabled by default for new root servers and VPS, existing VMs can now activate the feature in the SCP
  • Simple management in the server control panel or automated via API
Schematische Grafik: Firewall filtert eingehenden und ausgehenden Traffic nach Regeln.

Why an additional firewall makes sense

The firewall gives you an additional, easy-to-understand yet flexible option to significantly reduce the attack surface of your vServer at netcup. However, we strongly recommend that you also set up your own internal firewall solutions such as iptables or nftables on the server itself, even if you use the firewall feature from netcup.

 

The firewall provides basic protection. It supplements your measures with an upstream security layer in the network, for example to counteract unwanted public services or misconfigurations in the system, but does not replace protection via local server firewalls.

 

 

Notes and limitations

The firewall is available for all netcup server products from Generation 12 onwards and can be configured per server with immediate effect. The firewall is already activated by default for new orders. For existing servers (ordered before December 9, 2025), the firewall must be activated once in the SCP.

 

You can define up to 500 active rules per server and per public network interface in the firewall. Please note, however, that some rules are already predefined by default, for example to prevent email spamming such as netcup Mail block (default policy). You can remove these at any time after activation. For example, outgoing traffic on port 25 (SMTP) is blocked by default. This measure serves as a protective mechanism against outgoing e-mail spam. If you want to operate your server as a mail server, you can remove this rule manually at any time. In this case, however, make sure that your email configuration is complete and correct to avoid blocking by third-party providers or blacklists.

 

If no policies are assigned to a server, the firewall generally allows all traffic.

 

 

Management via SCP and API

The firewall can be activated and managed directly in the Server Control Panel (SCP). Policies can be created, edited and assigned to individual servers there. Alternatively, administration can be fully automated via the netcup API.

 

Don't miss out: Grab today's VPS 1000 G12 Pro deal in the advent calendar

If you don't yet have a server with netcup, today is the right time get one: From December 9, 08:00 am (CET) to December 10, 08:00 am you have the opportunity to secure yourself the VPS 1000 G12 Pro deal – a sneak peek at the upcoming VPS generation - only today with 100% more NVMe storage.

FAQs about the firewall