
What’s new:
- Contabo Firewall is now live and included free with every VPS and VDS instance
- It’s the first feature out of Contabo Labs, our new in-house development division
- The firewall runs at the network level – when activated, all inbound traffic is blocked by default until you define rules
- Configure everything directly from the Customer Control Panel, no iptables or separate installation needed
- One firewall can protect multiple instances, managed from a single place
- Outbound traffic stays completely unrestricted
- Find it at new.contabo.com under Network Services → Firewall
Today we’re launching Contabo Firewall – a free, built-in network firewall that comes with every VPS and VDS, new and existing. To use it you don’t need to purchase any Add-Ons or install anything new on your server. Just head to your Customer Control Panel and it’s already there.
This is also the first feature out of Contabo Labs, our new in-house development team focused on building tools that make managing your hosting setup faster and more practical. More on Contabo Labs below – but first, here’s what the Firewall actually does.
How It Works
The Firewall runs at the network level, sitting in front of your server entirely. When you activate it, all inbound traffic is blocked by default. From there, you define exactly what gets through – by port, protocol, or source IP.
A practical example: your web server accepts HTTPS on port 443, SSH is locked to your office IP, and everything else never reaches your OS. That means fewer open ports and no guesswork about what’s exposed.
Outgoing traffic stays completely unrestricted – the Firewall only controls what comes in.
Where to Find It
Go to new.contabo.com and navigate to Network Services → Firewall.
Quick note: your new.contabo.com credentials may differ from your my.contabo.com login. If you run into trouble, our support article covers the full setup process from start to finish.

Setting Up Rules
Rules are configured inside the Customer Control Panel under Network Services → Firewall. Create a firewall, give it a name, and start adding inbound rules.
For each rule, you define:
- Traffic type – predefined options like HTTPS, SSH, or MySQL, or a fully custom setup
- Protocol – TCP, UDP, or ICMP
- Port – single ports, comma-separated lists, or ranges (e.g. 8000–8100)
- Source – any IP, any IPv4/IPv6, a specific address, or a CIDR range
Predefined traffic types come pre-filled, which means setting up common services takes about thirty seconds. Once your rules are ready, assign your VPS or VDS instances to the firewall – the rules apply immediately.
Managing Multiple Servers
If you’re running several instances, you don’t have to configure each one separately. Apply a single firewall across multiple VPS or VDS instances and adjust rules from one place. Anyone who’s spent time repeating the same iptables setup on every new server will appreciate this.
What Is Contabo Labs?
Contabo Labs is our new internal division dedicated to building features that make the hosting experience more practical – tools for managing, monitoring, and securing your infrastructure directly from your control panel.
The Firewall is the first feature to come out of it. We’re building more, so watch this space!
We hope you enjoy the new Firewall feature.