# Cloud firewalls on Quake AI

Source: https://docs.quake.ai/docs/network/concepts/firewalls
Markdown: https://docs.quake.ai/docs/network/concepts/firewalls.md

---

# Cloud firewalls on Quake AI

Provider **firewalls**, **security lists**, and **cloud firewalls** filter traffic to VMs. On Quake AI port-level rules are **[security groups](/docs/network/concepts/security-groups)** in the Network service (OpenStack Neutron).

Security groups attach to **ports**, including instance network interfaces. Rules specify direction, protocol, ports, and remote CIDR or remote group. Default posture should deny inbound except what you explicitly allow.

## How other products map

| Provider | Their term | On Quake AI |
|---|---|---|
| AWS | Security group | [Security group](/docs/network/concepts/security-groups) |
| Hetzner / DigitalOcean | Cloud firewall | [Security group](/docs/network/concepts/security-groups) |
| Azure | Network security group (NSG) | [Security group](/docs/network/concepts/security-groups) |
| Google Cloud | VPC firewall rule | [Security group](/docs/network/concepts/security-groups) |

Host `iptables` on the instance is separate from cloud security groups. Use both when you need defense in depth.

## What to read next

- [Security groups](/docs/network/concepts/security-groups): rule model and stateful behavior
- [Create a security group](/docs/network/how-to/create-security-group): first inbound rules
- [Harden a production VM](/docs/compute/how-to/harden-production-vm): SSH and firewall baseline
