πŸ›‘οΈ
Beveiliging

Setting up Firewall Rules for Web Hosting

πŸ“… 8 October 2026 ✏️ 8 October 2026 ⏱ 5 min leestijd

Learn how to set up firewall rules for web hosting: which ports should be open, how to block IPs, and how to avoid common mistakes.

A firewall protects your web hosting against unwanted traffic by only allowing certain data traffic based on ports, IP addresses, and protocols. For a functioning website, you must at least properly configure ports for HTTP, HTTPS, mail, and SSH, while closing off the rest by default. In this article, you’ll read which rules you need, how to set them up, and which pitfalls to avoid.

What a firewall does for web hosting

A firewall monitors incoming and outgoing traffic on a server and determines based on rules whether this traffic is allowed or blocked. For web hosting, this mainly concerns protecting ports that don’t need to be publicly accessible, such as database ports or management access, while ports for your website and email should indeed remain open for visitors and mail servers.

Without proper firewall rules, a server is exposed to scans, brute-force attacks on login pages, and attempts to exploit vulnerable services. With the right settings, you limit the attack surface to only what’s truly necessary.

VisitorFirewallrules & portsWeb server

Which ports should you open

For a normally functioning website with email, you need a limited number of ports. The rest can be closed or restricted to trusted IP addresses.

  • Port 80 and 443 – for HTTP and HTTPS, needed so visitors can reach your website.
  • Port 25, 465, 587 – for sending email via SMTP.
  • Port 110/995 and 143/993 – for retrieving email via POP3 and IMAP.
  • Port 22 – for SSH access, preferably only accessible from your own IP address.
  • Database ports (e.g. 3306) – these should almost never be reachable from outside.

If there are services open that you don’t use, close those ports. The fewer open ports, the smaller the attack surface.

πŸ’‘ Tip: Always restrict SSH and management access to specific IP addresses instead of opening them up for everyone.

Setting up firewall rules in Plesk

Plesk has a built-in firewall module that lets you manage rules in a clear overview without having to work manually in configuration files. You’ll find this module in the Plesk control panel under the server management tools.

1

Open the firewall module

Log in to Plesk and go to the firewall module in the server management section. Here you’ll see an overview of all active rules and ports.

2

Check default rules

Plesk sets default rules for commonly used services such as web server, mail, and DNS. Check whether these match the services you actually use.

3

Add a custom rule

If you want to restrict a port to specific IP addresses, create a custom rule and specify which source IPs get access.

4

Close unused ports

Disable or remove rules for services that are not active, so these ports don’t remain unnecessarily reachable.

5

Apply the changes and test

Activate the new configuration and then check whether your website, email, and SSH access still work properly.

If you use business email alongside your website, also check whether the correct mail ports are open so sending and receiving keep working smoothly, see also business email.

Common mistakes and how to avoid them

A common mistake is completely disabling the firewall because an application isn’t working, instead of adjusting the specific port or rule. This leaves the door wide open for abuse.

Opening database ports for all IP addresses instead of only the required server addresses is also risky. Always restrict access to what’s strictly necessary.

Also, don’t forget to test rules after every change: an incorrectly configured rule can unintentionally block your own website or mail traffic. Document which rules you’ve changed and why, so you can quickly trace back if problems arise.

If you get stuck setting up rules, consult the knowledge base or contact support.

Frequently Asked Questions

Do I need to open port 21 for FTP?

Only if you actually use FTP. If you use SFTP via SSH, you don’t need this port separately.

Can a firewall make my website unreachable?

Yes, an incorrectly configured rule can block port 80 or 443, preventing visitors from loading your site. Always test after every change.

Is a firewall enough for complete security?

No, a firewall is one layer of security. Combine this with strong passwords, up-to-date software, and regular backups.

Can I completely block an IP address?

Yes, in the firewall module you can completely block specific IP addresses or ranges from all traffic to the server.

Do firewall rules work the same for every hosting package?

This depends on the type of hosting and control panel. With web hosting using Plesk, this is done via the firewall module; with other providers this may differ.

Conclusion

Good firewall rules ensure that only necessary traffic reaches your server: open ports for web, mail, and management, close the rest, and restrict sensitive access to trusted IP addresses. Always test changes carefully to prevent your own website or email from becoming unreachable.

View web hosting β†’

Was dit artikel nuttig?