Skip to main content

Network Firewall

tip

By default, only the ports required by your deployed application are open.

Restrict access by IP​

From the dashboard, open Security, then Show Settings on the Firewall row.

Firewall settings in the Security tab

From there you can add, edit, or remove rules to open a port to the internet, or only to a specific target IP.

info

Every service comes preconfigured with firewall rules that match the software you deploy.

warning

Keep port 80 open to any IPv4/IPv6, or Let's Encrypt cannot generate an SSL certificate.

Ports used by Elestio automation​

MandatoryDirectionProtocolPortUsage
YesInputTCP22Automation SSH
NoInputUDP4242Nebula / Global IP
NoInputTCP18345VS Code
NoInputTCP18374Open Terminal
NoInputTCP18346File Explorer
NoInputTCP18445Tail Logs
NoInputTCP18344Terminal

Ports marked No are needed only if you use the matching tool and have enabled the global private IP feature.