> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nyru.net/llms.txt
> Use this file to discover all available pages before exploring further.

> Our Firewall Panel offers comprehensive rule configuration options to protect your services against various DDoS attacks. This documentation explains how to create and manage custom security rules.

# Firewall Rules

## **Ready Rules**

For quick protection setup:

* **Simple Configuration**: Just select port, application profile, and destination IP
* **Instant Activation**: Rules become active in less than 1 second
* **Common Protection**: Pre-optimized profiles for typical attack scenarios

<img src="https://mintcdn.com/nyruserviceslimited/g2Cbo6Pn6ErLkrRf/images/rules1.png?fit=max&auto=format&n=g2Cbo6Pn6ErLkrRf&q=85&s=77ee798470eebbe889e60f901eaf13b8" alt="Rules1 Pn" width="969" height="670" data-path="images/rules1.png" />

## **Advanced Rules**

For customized security requirements:

### **Packet Filtering Options**

* **Sequence Number**: Rules are processed according to sequence numbers
* **Protocol Selection**: Choose from TCP, UDP, ICMP, or over 140 different protocols
* **Source Prefix Lists**: Define specific IP ranges
* **Destination Settings**: Target specific IP addresses and ports

### **Deep Inspection**

* **Packet Length**: Filter packets by size
* **Payload Analysis**: Content-based filtering
* **Geographic/ASN Filtering**: Control traffic by country or AS number
* **TCP Flag Control**: Define specific TCP flag combinations

<img src="https://mintcdn.com/nyruserviceslimited/g2Cbo6Pn6ErLkrRf/images/rules2.png?fit=max&auto=format&n=g2Cbo6Pn6ErLkrRf&q=85&s=e70265e4455d8a5d2f77f65d5cb6d5d6" alt="Rules2 Pn" width="876" height="920" data-path="images/rules2.png" />

<img src="https://mintcdn.com/nyruserviceslimited/g2Cbo6Pn6ErLkrRf/images/rules3.png?fit=max&auto=format&n=g2Cbo6Pn6ErLkrRf&q=85&s=63300e4163db506b4f27013ccbfa7276" alt="Rules3 Pn" width="914" height="931" data-path="images/rules3.png" />

## **Available Actions**

Choose how to handle matched traffic:

* **Discard**: Block matching packets completely
* **Accept with Destination Ratelimit**: Allow traffic with limits to destination IP
* **Accept with Source Ratelimit**: Allow traffic with limits from source IP
* **Accept with Rule Limit**: Apply total traffic limit for the specific rule
* **Custom Configuration**: Define completely customized behavior
* **Set Application Profile with Source Ratelimit**: Apply application profile with source limits

## **Sequential Processing**

Firewall rules are processed according to sequence numbers:

* **Closed Chain Requirement**: Rules should form an uninterrupted sequence (e.g., 1,2,3,4,5)
* **First Rule**: Every destination IP prefix starts with sequence number one (1)
* **Processing Flow**: Open chains (e.g., 1,2,4,5) stop processing after the last matching rule
* **Rule Limit**: Maximum of ten (10) rules due to system limitations

<img src="https://mintcdn.com/nyruserviceslimited/g2Cbo6Pn6ErLkrRf/images/rules4.png?fit=max&auto=format&n=g2Cbo6Pn6ErLkrRf&q=85&s=a4c72e9c50d1847343a9d9427773d785" alt="Rules4 Pn" width="1865" height="921" data-path="images/rules4.png" />

All rule changes take effect in less than 1 second, allowing quick response to DDoS attacks. You can monitor rule performance and matching statistics in real-time through the Firewall Panel.
