How the cloud firewall works
Rules run at the hypervisor level, outside your VMs, so the cloud firewall filters traffic before it reaches an instance. There’s nothing to install or keep patched inside the VM, and because the rules live outside it, they keep applying even if the VM itself is misconfigured or compromised. You write a rule set once and attach it to the machines it should protect.
What you configure
Define inbound and outbound network firewall rules by port, protocol and source. Open only what a service needs, port 80 and 443 for web traffic, and close everything else by default. Restrict administrative ports like SSH and RDP to known addresses so they’re never exposed to the whole internet. Outbound rules let you limit what a VM can reach, which contains the damage if one is ever breached.
Apply one rule set across many VMs
Cloud-based firewalls are most useful at scale. There is no need to run a separate virtual machine firewall on each box. You keep a rule set in one place and attach it to a group of VMs. The model will be familiar to teams that use security groups elsewhere: define a policy once, then apply it wherever those VMs share the same exposure. Change a rule and it applies everywhere that set is used, and a rebuilt or replaced VM picks up the same protection automatically.
Lock down a back-end service
Expose your web tier on 80 and 443. Apply a separate rule set to your database VMs that accepts connections only from the web tier over your private network. Keep admin access limited to your own IP range and deny everything else. One change to the rule set updates every VM it covers, so a fleet stays consistent without touching each box.
Built on the Krystal Cloud networking platform
The cloud firewall protects the Virtual Machines you run on Krystal. It’s part of Krystal Cloud’s networking, with DDoS protection on every VM and a 100G backbone with redundant paths across London, Amsterdam and New York. For the full platform detail, see Krystal Cloud networking.
SDN Private Network pricing
Firewall is included with every VM at no extra cost, however many rule sets you create and however many machines you protect. Full pricing for the rest of the platform is on the cloud pricing page.
View all pricingWhy choose Krystal as a cloud firewall provider
UK-based engineering support
Our support team are engineers based in the UK. When you get in touch, you're speaking to someone who understands the platform and can work with you to get it sorted.
Included at no extra cost
Firewall is included with every VM at no extra cost. You can cancel whenever you want.
Certified security
Krystal holds ISO 27001 certification for information security and Cyber Essentials Plus, the UK government's cybersecurity certification.
Matched with renewable energy
We match our energy use with renewables, so enough renewable energy is produced to cover what we consume. Krystal is a Certified B Corp and 1% for the Planet member, with over five million trees funded through our reforestation programme.
Start building today
Sign up and you’ll be up and running on Krystal Cloud in less than a minute.
Cloud Enquiry
Take the first step
General enquiries
Call us
Call the Sales team on +1 833 858 1337
Email us
Email our team on sales@krystal.io
Learn more about our cloud services
Pricing
Transparency is key. We're upfront with our pricing structure meaning you always know how much you'll pay.
Documentation
Read our docs and see how you might use Krystal Cloud in your organization.
B Corp Certified
Rest easy knowing your cloud runs on 100% renewable energy from a certified B Corporation.
FAQs
The most-asked questions about our services and billing. Can’t find the answer? Check our Knowledge Base or drop us a line on .Still have questions?
We’re happy to help answer any questions you have.