InfraNestInfraNest

Servers & Cloud

Cloud firewall management across every provider

Bring every cloud firewall into one editor — Hetzner, DigitalOcean, AWS and the rest. Write inbound and outbound rules the same way everywhere, roll a safe baseline across dozens of servers, and get told the moment a port opens to the whole internet.

Free plan · No credit card · Connect a provider in 2 minutes

Firewall rules9 firewalls · 3 providers
PortSourceAction
443/tcp0.0.0.0/0Allow
80/tcp0.0.0.0/0Allow
22/tcp0.0.0.0/0Allow
5432/tcp10.0.0.0/16Allow
3306/tcp0.0.0.0/0Allow

The same rule table, whichever cloud runs the server.

Works with your clouds

HetznerDigitalOceanAWSand moreSee all 42 →

One editor for every cloud firewall

Your firewalls at Hetzner, DigitalOcean, AWS and the rest are imported automatically and edited the same way — inbound and outbound rules, ports, protocols and sources in one consistent table. No more relearning a different rule builder in every console, or wondering whether “deny” means the same thing here as it does there.

  • Auto-imported the moment you connect a provider
  • Inbound and outbound rules in one shared format
  • Every change written straight back to the provider
Firewall · web-prod-015 inbound rules
HTTPS443/tcp from anywhereAllow
HTTP80/tcp from anywhereAllow
SSH22/tcp open to 0.0.0.0/0Restrict →
POSTGRES5432/tcp from private networkAllow
ICMPPing from anywhereAllow

Reusable templates, not copy-paste

Define a firewall once — “Public web”, “Database”, “Internal only” — and apply it to as many servers as you like, across providers. Change the template and every server using it updates together, so a new allow-rule reaches all thirty machines instead of the four you remembered.

  • One template applied to any number of servers
  • Edit once, and every linked server follows
  • Works the same whoever the provider is
Applying template “Public web”
Baseline rules loaded0s
Matched to 12 servers across 3 clouds3s
Rules pushed to each provider11s
All servers in sync with the template18s

One edit, twelve servers, three providers.

A standing check on open ports

Every firewall is checked continuously for risky exposure — SSH or RDP open to the world, a public database port, a rule that no longer matches its template. You get a plain-language finding and a one-click fix, before a stray rule becomes an incident, and drift back to the baseline is caught the same way.

  • Flags SSH, RDP and database ports open to anywhere
  • Detects drift from the template a server should follow
  • One-click fix written back where the API allows it
Exposure check · 9 firewalls3 of 9 need attention
SSH22/tcp open to the world on db-prod-02Fix →
MYSQL3306/tcp reachable from anywhereFix →
DRIFTapi-03 no longer matches “Public web”Reapply →
RDP3389/tcp closed on every serverPassed
EGRESSOutbound rules within baselinePassed

Everything else it handles

The parts that are only interesting when you need them.

Inbound and outbound rules

Control egress as well as ingress, with the same editor and the same checks — not an afterthought buried in an advanced tab.

Dynamic IP allow-rules

Pin SSH or admin access to a Dynamic IP so remote access follows your connection, and never the whole internet.

Rule labels and comments

Every rule carries a note on why it exists, so the person reviewing it in six months is not guessing.

Bulk apply and revoke

Add or pull a rule across every server on a template in one action, instead of editing consoles one by one.

Private network rules

Allow traffic between servers on a private network without ever exposing the port publicly.

Preview before it saves

See exactly which servers and rules a change touches before anything is written to a provider.

Provider-native mapping

Rules translate to each cloud’s own firewall model, so what you see in InfraNest is what actually runs.

Full audit trail

Every rule change recorded with who made it and when, exportable for review or compliance.

See your own firewalls in about two minutes

Connect one provider with a read-only token. Nothing changes until you say so.

Editing firewall rules by hand vs InfraNest

The difference between hoping nothing is exposed and knowing it isn’t.

By hand

  • A different rule builder in every provider console
  • No warning when SSH or a database is open to the world
  • Every server’s rules quietly drifting from the baseline
  • Your office IP whitelisted by hand, again, when it changes

With InfraNest

  • Every firewall in one consistent editor
  • A standing check that flags risky ports with one-click fixes
  • Templates that roll a safe baseline across servers
  • Allow-rules that follow a Dynamic IP so access stays yours

Pairs well with

Frequently asked

Which cloud providers are supported?

Hetzner today, with DigitalOcean, AWS and more on the way. What you can edit depends on what each provider’s firewall API exposes — the integrations page lists exactly what works where.

Does InfraNest replace my cloud firewall?

No. InfraNest manages the native firewall each provider already gives you. Rules are written back to the cloud, so what runs is the provider’s own firewall — just edited from one place.

What happens to rules I already have?

They are imported as they are when you connect a provider, nothing is dropped or rewritten. You keep editing the same rules, just in one consistent editor instead of six consoles.

Will a template overwrite manual rules on a server?

Only the rules the template manages, and never silently — you see exactly what a change touches before it saves. Server-specific rules you add on top stay put.

How does the exposure check decide what is risky?

It looks for well-known danger patterns — SSH, RDP or database ports open to 0.0.0.0/0, and drift from the template a server should follow. Each finding explains itself, and you choose whether to apply the fix.

Know nothing is exposed

Connect a provider and see every firewall rule you already run.

Start for free