FIREWALL

Network-layer access control.

UFW rule management with per-rule comments, audit logging, and drift detection. Add a port, allow an IP, deny a CIDR — without SSH.

cloudnan.com / dashboard / firewall

Firewall (UFW)

6 rules · status: active

#ActionMatchDirectionComment
  • [1]allow22/tcp · from anyinSSH ops access
  • [2]allow80/tcp · from anyinHTTP
  • [3]allow443/tcp · from anyinHTTPS
  • [4]allow5432/tcp · from 10.0.0.0/8inPostgres VPC only
  • [5]deny23/tcp · from anyinBlock telnet
  • [6]deny185.220.101.34/32inAI block_ip · brute force

How it works

What happens under the hood.

  1. 01

    Read current rules

    Agent runs `ufw status numbered` and surfaces the rule list in the panel.

  2. 02

    Add via panel or AI

    Allow port 5432 from your office IP — through a click or by asking the AI Assistant.

  3. 03

    Approval gate

    Adding a firewall rule is a tier-Approve operation. Even the AI prompts you before changing UFW state.

  4. 04

    Audit + drift

    Every rule change is logged. Drift detection alerts you if someone edits ufw outside the panel.

What you get

The capabilities that ship.

Allow / deny rules

Per-port, per-IP, per-CIDR. Both inbound and outbound supported.

Per-rule comments

Every rule carries a why-string so the next operator (or you in 6 months) knows why it exists.

Block IP fast

AI tool `block_ip` for incident response — drops a deny rule in seconds when an abuser is hitting your box.

Drift-tracked

Anyone edits /etc/ufw/* outside the panel and you'll see it in drift findings.

FAQ

Common questions.

What if my server uses iptables / nftables directly?
UFW writes to nftables under the hood; the panel reads either. If you have hand-written iptables rules outside UFW, they're visible but Cloudnan won't modify them.
Is this just a wrapper around `ufw allow`?
Approximately yes — that's the point. Cloudnan adds the audit log, the drift tracking, the AI tooling, and the per-rule comment. The underlying mechanism is the standard Linux firewall.

Your fleet deserves better.

Get started in minutes.

Deploy agents on your servers, connect securely, and take full control. Start free, upgrade when ready.

  • 7-day free trial
  • No credit card
  • Cancel anytime