Canadian cloud in Montréal · VMs from 8.50 CAD/month

What you get

Close what you did not decide to open.

  • Protection

    Nothing to install

    Your rules hold whatever runs in the machine: a misconfigured service or a disabled system firewall changes nothing.

  • Reuse

    One set, many machines

    Attach the same firewall to as many machines as you like. Change a rule once, every machine follows.

  • Inbound

    Ports and sources

    TCP, UDP, ping or everything, on ports or ranges, from anywhere or from listed IPv4 and IPv6 ranges.

  • Outbound

    When you need it

    Outbound stays free until you add an outbound rule; then only what you open goes out, plus DNS.

  • Always reachable

    Console and private network

    Replies to the machine's own connections, its private networks and the web console are never filtered.

  • Automation

    API and MCP

    The same firewalls from the REST API or an AI agent, which is told to keep SSH open.

A web firewall: SSH from the office only, the web open to everyone, HTTPS only going out.
A web firewall: SSH from the office only, the web open to everyone, HTTPS only going out.

In practice

A firewall, attached in one call.

In the console, shortcuts fill in the usual rules (SSH, Web, RDP, databases, WireGuard). Through the API, describe the rules, then attach the firewall to a machine: inbound traffic no rule opens is dropped within seconds.

The step-by-step demo

bash
curl -s -X POST https://api.ffxf.net/v1/firewalls \
  -H "Authorization: Bearer $FFXF_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"name": "web", "rules": [
        {"protocol": "tcp", "ports": "22", "sources": ["203.0.113.0/24"]},
        {"protocol": "tcp", "ports": "80,443"},
        {"protocol": "icmp"}]}'

curl -s -X POST https://api.ffxf.net/v1/firewalls/3/members \
  -H "Authorization: Bearer $FFXF_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"vm": 150}'

Limits

What to know before you start.

FFxF · Montréal

Protect your machines in a few clicks.

Create a firewall from the console, keep SSH open, attach it, and check from the outside.

Support & discussions

Technical questions, incident reports, or infrastructure discussions, the team is reachable on Discord, Telegram, X, Instagram, Reddit, and IRC.