Skip to content
fugoku
Get Started

Firewalls

Distributed stateful firewall at the network edge. Default-deny, L3/L4/L7 rules, DDoS protection, and zero egress fees. Full API control.

At a Glance

Per-project/per-networkDeployment
Line rateThroughput
UnlimitedRules
IncludedEgress

Firewall Features

Enterprise protection included

Distributed Edge Enforcement

Firewall rules enforced at the network edge — not on your instances. No agent, no performance impact, no bypass.

Stateful L3/L4/L7

Full stateful inspection. Layer 3/4 (IP, port, protocol) plus Layer 7 (HTTP, TLS SNI, DNS). Default-deny by default.

DDoS Protection

Always-on scrubbing at the edge. SYN flood, UDP reflection, volumetric attacks absorbed before reaching your network.

GeoIP & Threat Intel

Block/allow by country, ASN, or threat feed. Real-time threat intelligence feeds updated continuously.

Flow Logs

Structured flow logs to your storage bucket or SIEM. Accepted, dropped, and rejected flows. JSON/Parquet formats.

Zero Egress

All firewall traffic — including DDoS scrubbing — included. No per-GB or per-rule charges.

Rule Types

Granular control at every layer

L3/L4 Rules

IP (CIDR), port, protocol (TCP/UDP/ICMP/ICMPv6), ICMP type/code. Stateful — return traffic auto-allowed.

L7 Application Rules

HTTP host/path/method/header, TLS SNI, DNS query/response, custom regex patterns. Deep packet inspection.

GeoIP & Threat

Country/continent/ASN blocking. Real-time threat intel feeds (malware C2, phishing, botnets). Auto-updated.

How It Works

Deploy edge firewall rules in seconds.

1
Define Policy
Create rule groups: ingress/egress, L3/L4/L7, logging
2
Attach to Network
Apply to private network, VLAN, or instance group
3
Instant Enforcement
Rules pushed to edge fabric. Line-rate, no restart

Edge Enforcement, Zero Overhead

Rules run on our programmable fabric — not your instances. No agents, no CPU steal, no performance impact. And you can update rules instantly without restarts or downtime.

And when you need help, our security engineers are a Slack message away.

Secure Your Network at the Edge

Default-deny. L3/L4/L7. DDoS protection. Zero egress.