The Plesk Firewall gives you control over incoming and outgoing server traffic, allowing you to block unwanted connections and protect important services. In this article, you’ll learn how to access the firewall, how to create rules, and how to block or whitelist IP addresses for administrative access.
Accessing the Plesk Firewall
Log in to your Plesk control panel and go to Tools & Settings in the left menu. Depending on your Plesk version, you’ll find the Firewall or Fail2Ban option here. Only users with administrator rights can modify firewall rules.
Creating Firewall Rules
A firewall rule determines whether traffic on a specific port and protocol is allowed (Allow) or denied (Deny). This is useful, for example, to shield a database port or to grant access to SSH only to certain IPs.
Open the firewall settings
Go to Tools & Settings > Firewall and click “Add Rule”.
Choose the rule type
Select Allow or Deny and choose the protocol: TCP, UDP, or both.
Enter the port and IP
Specify the port number, for example 443 for HTTPS or 3306 for MySQL, and optionally a specific IP address.
Save the rule
Click “Apply” or “Save”. The rule becomes active immediately, so afterward test whether your website and email are still reachable.
Blocking and Allowing IP Addresses
A common use of the firewall is blocking IP addresses that generate suspicious traffic, and whitelisting IPs that should always have access, such as your office or home network.
Blocking IP addresses: go to Firewall > IP Address Bans and enter the IP address. You can also block an entire range using CIDR notation, for example 192.168.1.0/24.
Whitelisting IP addresses: create an Allow rule for the specific IP, for example for SSH access on port 22 or for access to the Plesk control panel. This prevents you from accidentally locking yourself out.
Fail2Ban complements this: this system automatically detects repeated failed login attempts and temporarily blocks the associated IP address, without you having to manually create a rule.
Common Ports and Applications
Some ports that regularly come up in firewall configuration: ports 80 and 443 for website traffic (HTTP/HTTPS), port 22 for SSH, port 21 for FTP, and port 3306 for MySQL. Block ports you don’t actively use, and restrict access to administrative ports to known IP addresses.
Note that strict firewall rules can also affect your business email, for example when SMTP or IMAP ports are accidentally blocked. Test after every change whether mail is still sent and received correctly. If in doubt, consider documenting changes first in the knowledge base or consulting with support before applying them to a production server.
Frequently Asked Questions
Can I accidentally block my own IP address?
Yes, this happens regularly. Always whitelist your own IP address before setting up a strict Deny rule for administrative access.
What is the difference between Plesk Firewall and Fail2Ban?
Plesk Firewall is manual rule configuration for ports and IPs. Fail2Ban is an automatic system that detects suspicious login attempts and temporarily blocks IP addresses.
How quickly do firewall rules become active?
Usually almost immediately after saving, although it can sometimes take a few seconds before the rule is fully applied.
Can I export or migrate firewall settings?
Plesk offers export functionality for firewall configurations, useful for a backup or when switching to Tandata.
Does the firewall affect my domain name or DNS?
No, firewall rules apply to server traffic and ports, not to the DNS settings of your domain names.
Conclusion
With the Plesk Firewall, you secure your server by specifically managing incoming and outgoing traffic through Allow and Deny rules, IP blocks, and whitelisting. Always test changes carefully to avoid important services such as email or SSH becoming unintentionally inaccessible.