Two devs each create a temporary Hetzner firewall. Six months later: fifteen servers, eight inconsistent groups, port 22 open on three for debug.
Hetzner Cloud offers effective managed firewall — treat as infrastructure as code, not post-deploy checkbox.
Without group conventions, each server multiplies a forgotten rule.
Group model
fw-bastion SSH from admin IP; fw-web 80/443; fw-db from web only; fw-worker no public inbound.
| Group | Inbound | Outbound |
|---|---|---|
| bastion | Restricted SSH | Minimal |
| web | 80/443 | DB + updates |
Rules before tenth server
Terraform or API, default deny inbound, SSH via bastion, documented egress, monthly temp rule review.
Classic mistakes
Inconsistent cloud + OS rules, prod group copied to staging, forgot detach firewall, no SIEM logs.
The peak: horizontal scale = scale mistakes
Exception governance
Every temporary debug rule needs expiry date and owner. Otherwise port 22 stays open months. Fold cloud firewall review into same ritual as cert or admin account review.
If mixing Hetzner cloud and other provider, document which layer filters what — frequent confusion between cloud firewall, network firewall, and OS firewall on VM.
Go further with the inquiry
Apply the article to your concrete case: what volume, what service level, what contractual constraints from clients or regulators? Write answers before opening the pricing page. Request written documents — full grid, DPA, certification scope, renewal terms — not homepage screenshots.
Compare at least two providers via the directory and compare tool on identical thirty-six-month assumptions. Share the short list with whoever signs the contract and whoever operates infrastructure daily. Archive terms dated at subscription so due diligence is defensible later.
Go further with the inquiry
Apply the article to your concrete case: what volume, what service level, what contractual constraints from clients or regulators? Write answers before opening the pricing page. Request written documents — full grid, DPA, certification scope, renewal terms — not homepage screenshots.
Compare at least two providers via the directory and compare tool on identical thirty-six-month assumptions. Share the short list with whoever signs the contract and whoever operates infrastructure daily. Archive terms dated at subscription so due diligence is defensible later.
Exception governance
Every temporary debug rule needs expiry date and owner. Otherwise port 22 stays open months. Fold cloud firewall review into same ritual as cert or admin account review.
If mixing Hetzner cloud and other provider, document which layer filters what — frequent confusion between cloud firewall, network firewall, and OS firewall on VM.
Exception governance
Every temporary debug rule needs expiry date and owner. Otherwise port 22 stays open months. Fold cloud firewall review into same ritual as cert or admin account review.
If mixing Hetzner cloud and other provider, document which layer filters what — frequent confusion between cloud firewall, network firewall, and OS firewall on VM.
Decide and move forward without blind spots
Start by framing your real scenario on one page: volumes, client constraints, required support level, and a thirty-six-month budget including domain, backup, and essential add-ons. Compare at least two hosts via the directory and compare tool with identical assumptions, archive pricing grids dated on subscription day, then have both the contract signer and daily infrastructure operator validate the short list.
Frequently asked questions
Hetzner firewall how?
Stateful upstream; groups attached to VMs.
Cloud or OS firewall?
Both — cloud reduces surface, OS refines.
Structure before scale?
Role groups, default deny, SSH bastion.
GDPR protection?
Useful security measure; not DPA/encryption substitute.
Set groups before servers — or you firewall catch-up.
