Skip to main content
Cloud / STACKIT / Products / STACKIT Network Security - Firewall & Security Groups

STACKIT Network Security - Firewall & Security Groups

STACKIT Network Security: Security Groups, Unified Firewall, and STACKIT Network Area from Germany. GDPR-compliant.

Network
Pricing Model Security groups and networking included with infrastructure resources; Unified Firewall currently free (free tier)
Availability STACKIT regions in Germany and Austria
Data Sovereignty Traffic stays in German/European data centers
Reliability SLA as published by the provider SLA

What is STACKIT Network Security?

STACKIT Network Security bundles the security features around STACKIT networks: security groups acting as stateful host firewalls for individual instances, the central Unified Firewall for cross-project management, and connectivity options via STACKIT Network Area (SNA) and VPN for hybrid scenarios. STACKIT operates the underlying infrastructure from data centers in Germany and Austria.

Core Features

  • Security Groups: Stateful firewall rules per instance, reusable across multiple servers; the default rule blocks inbound traffic until explicitly allowed. The security group pages in the STACKIT Portal were overhauled in July 2026 (new creation wizard, filtering for rules, overview of NICs using a given rule)
  • Unified Firewall: Central dashboard that combines security groups, database ACLs, and public IP rules across projects, including a rule wizard with templates and project-level rule export (GA since July 2026, regions EU01 and EU02)
  • STACKIT Network Area (SNA): Private transfer network connecting multiple projects within an organization at the network level, without traversing the public internet
  • VPN connectivity: Managed IPsec VPN gateway (IKEv2) securely connects on-premises sites to the STACKIT Network Area
  • API-first: Manage security groups and firewall rules via API, CLI, and the Terraform provider

Typical Use Cases

Multi-tier architectures: Web, application, and database tiers are isolated from each other via separate security groups.

Microservices networking: Kubernetes workloads on STACKIT Kubernetes Engine use security groups and network segmentation to secure traffic between services.

Hybrid cloud connectivity: On-premises data centers securely connect to the STACKIT Network Area via a managed IPsec VPN gateway (IKEv2).

Central security management: Teams with multiple STACKIT projects use the Unified Firewall to manage security rules in one place instead of per project.

Benefits

  • Data sovereignty: Network traffic stays in German/European data centers
  • Stateful security groups: Included in infrastructure resource pricing
  • Central visibility: Unified Firewall reduces operational complexity across multiple projects
  • GDPR-compliant: Operated without US-CLOUD Act risk

Integration with innFactory

As an official STACKIT partner, innFactory supports you with network and security architecture: segmentation concepts using security groups, building STACKIT Network Area and VPN connections, and rolling out the Unified Firewall for central security management.

Available Tiers & Options

Unified Firewall

Strengths
  • Central dashboard for security groups, ACLs, and public IPs
  • Rule wizard with templates
  • Project-level rule export for audits
  • Currently free
Considerations
  • No traffic inspection (IDS/IPS, geo-blocking, URL filtering)

Typical Use Cases

Multi-tier application isolation
Microservices networking
Hybrid cloud connectivity via VPN
Central security management across multiple projects

Frequently Asked Questions

What is STACKIT Network Security?

Network Security bundles the security services around STACKIT networks: security groups acting as host firewalls, the central Unified Firewall dashboard, and connectivity options via STACKIT Network Area (SNA) and VPN.

Are security groups stateful?

Yes, security groups track connection state and automatically allow return traffic without separate rules. By default, all outbound traffic is allowed and inbound traffic must be explicitly permitted.

What is the STACKIT Unified Firewall?

The Unified Firewall combines security groups, database ACLs, and public IP rules into a central dashboard across multiple projects. STACKIT's release notes dated July 7, 2026 confirm general availability (GA) on project level ("STACKIT Unified Firewall is now Generally Available"), including EU02 region support, project-level rule export, and free-tier access; a navigation badge in parts of the documentation still shows an outdated "Beta" label. It is offered in the EU01 and EU02 regions and is currently free to use.

How do I connect multiple STACKIT projects or on-premises networks?

STACKIT Network Area (SNA) connects multiple projects via a private transfer network. For hybrid scenarios, on-premises infrastructure can be securely connected to the SNA via a managed IPsec VPN gateway (IKEv2).

Is DDoS protection available?

STACKIT offers integrated DDoS protection primarily for anycast DNS as part of its Domains, DNS & SSL services. For individual compute resources, a combination of security groups, Unified Firewall, and architectural measures is recommended.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.

STACKIT Partner

innFactory is an official STACKIT Partner. We provide consulting, implementation, and managed services for the sovereign cloud.

STACKIT Official Partner

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

Google Cloud

Certificate Manager - Central TLS Certificate Management

Certificate Manager acquires, manages, and deploys TLS certificates for Cloud Load Balancing, Secure Web Proxy, and …

Pricing Pricing as published on the official …
SLA SLA as published by the provider
Compare →
Google Cloud

Cloud Domains - Domain Registration in Google Cloud

Cloud Domains lets you register and manage domains directly in Google Cloud, with billing through Cloud Billing and …

Pricing Per top-level domain pricing as …
SLA SLA as published by the provider
Compare →
Google Cloud

Data Transfer Essentials - Data Transfer Between Cloud Providers

Data Transfer Essentials provides cost-optimized data transfer between the services of an application that resides …

Pricing Currently offered at no charge when used …
SLA SLA as published by the provider
Compare →
Google Cloud

Secure Access Connect - Attach SSE Services to NCC Gateway

Secure Access Connect lets you connect security service edge products to NCC Gateway for security processing and secure …

Pricing Billed according to NCC Gateway pricing …
SLA SLA as published by the provider
Compare →
Google Cloud

Service Extensions - Custom Code in the Network Data Path

Service Extensions inserts custom code into the data path of Cloud Load Balancing, Media CDN, and Secure Web Proxy, as …

Pricing Billed per invocation: plugins on Cloud …
SLA As published by the provider / see official documentation
Compare →
Google Cloud

Telecom Network Automation - Cloud-Native Automation for Telecom Networks

Telecom Network Automation is Google's managed cloud implementation of the open source Nephio project for intent-driven …

Pricing Pay-as-you-go per automated vCPU per …
SLA SLA per provider / see official documentation
Compare →

70 comparable products found across other clouds.

Ready to start with STACKIT Network Security - Firewall & Security Groups?

Our certified STACKIT experts help you with architecture, integration, and optimization.

Schedule Consultation