Firewalls
Distributed stateful firewall at the network edge. Default-deny, L3/L4/L7 rules, DDoS protection, and zero egress fees. Full API control.
At a Glance
Firewall Features
Enterprise protection included
Distributed Edge Enforcement
Firewall rules enforced at the network edge — not on your instances. No agent, no performance impact, no bypass.
Stateful L3/L4/L7
Full stateful inspection. Layer 3/4 (IP, port, protocol) plus Layer 7 (HTTP, TLS SNI, DNS). Default-deny by default.
DDoS Protection
Always-on scrubbing at the edge. SYN flood, UDP reflection, volumetric attacks absorbed before reaching your network.
GeoIP & Threat Intel
Block/allow by country, ASN, or threat feed. Real-time threat intelligence feeds updated continuously.
Flow Logs
Structured flow logs to your storage bucket or SIEM. Accepted, dropped, and rejected flows. JSON/Parquet formats.
Zero Egress
All firewall traffic — including DDoS scrubbing — included. No per-GB or per-rule charges.
Rule Types
Granular control at every layer
L3/L4 Rules
IP (CIDR), port, protocol (TCP/UDP/ICMP/ICMPv6), ICMP type/code. Stateful — return traffic auto-allowed.
L7 Application Rules
HTTP host/path/method/header, TLS SNI, DNS query/response, custom regex patterns. Deep packet inspection.
GeoIP & Threat
Country/continent/ASN blocking. Real-time threat intel feeds (malware C2, phishing, botnets). Auto-updated.
How It Works
Deploy edge firewall rules in seconds.
Edge Enforcement, Zero Overhead
Rules run on our programmable fabric — not your instances. No agents, no CPU steal, no performance impact. And you can update rules instantly without restarts or downtime.
And when you need help, our security engineers are a Slack message away.
Secure Your Network at the Edge
Default-deny. L3/L4/L7. DDoS protection. Zero egress.