What is STACKIT Network Security?
STACKIT Network Security bundles the security features around STACKIT networks: security groups acting as stateful host firewalls for individual instances, the central Unified Firewall for cross-project management, and connectivity options via STACKIT Network Area (SNA) and VPN for hybrid scenarios. STACKIT operates the underlying infrastructure from data centers in Germany and Austria.
Core Features
- Security Groups: Stateful firewall rules per instance, reusable across multiple servers; the default rule blocks inbound traffic until explicitly allowed
- Unified Firewall (beta): Central dashboard that combines security groups, database ACLs, and public IP rules across projects, including a rule wizard with templates
- STACKIT Network Area (SNA): Private transfer network connecting multiple projects within an organization at the network level, without traversing the public internet
- VPN connectivity: IPsec-based VPN appliance (strongSwan) securely connects on-premises sites to the STACKIT Network Area
- API-first: Manage security groups and firewall rules via API, CLI, and the Terraform provider
Typical Use Cases
Multi-tier architectures: Web, application, and database tiers are isolated from each other via separate security groups.
Microservices networking: Kubernetes workloads on STACKIT Kubernetes Engine use security groups and network segmentation to secure traffic between services.
Hybrid cloud connectivity: On-premises data centers securely connect to the STACKIT Network Area via an IPsec VPN appliance.
Central security management: Teams with multiple STACKIT projects use the Unified Firewall to manage security rules in one place instead of per project.
Benefits
- Data sovereignty: Network traffic stays in German/European data centers
- Stateful security groups: Included in infrastructure resource pricing
- Central visibility: Unified Firewall reduces operational complexity across multiple projects
- GDPR-compliant: Operated without US-CLOUD Act risk
Integration with innFactory
As an official STACKIT partner, innFactory supports you with network and security architecture: segmentation concepts using security groups, building STACKIT Network Area and VPN connections, and rolling out the Unified Firewall for central security management.
Available Tiers & Options
Security Groups
- Stateful host firewall per instance
- Reusable across multiple servers
- Included in infrastructure pricing
- Managed per project/resource
Unified Firewall (beta)
- Central dashboard for security groups, ACLs, and public IPs
- Rule wizard with templates
- Currently free
- Beta status, feature set still growing
Typical Use Cases
Frequently Asked Questions
What is STACKIT Network Security?
Network Security bundles the security services around STACKIT networks: security groups acting as host firewalls, the central Unified Firewall dashboard, and connectivity options via STACKIT Network Area (SNA) and VPN.
Are security groups stateful?
Yes, security groups track connection state and automatically allow return traffic without separate rules. By default, all outbound traffic is allowed and inbound traffic must be explicitly permitted.
What is the STACKIT Unified Firewall?
The Unified Firewall (currently in beta) combines security groups, database ACLs, and public IP rules into a central dashboard across multiple projects. It is currently free to use.
How do I connect multiple STACKIT projects or on-premises networks?
STACKIT Network Area (SNA) connects multiple projects via a private transfer network. For hybrid scenarios, on-premises infrastructure can be securely connected to the SNA via an IPsec VPN appliance.
Is DDoS protection available?
STACKIT offers integrated DDoS protection primarily for anycast DNS as part of its Domains, DNS & SSL services. For individual compute resources, a combination of security groups, Unified Firewall, and architectural measures is recommended.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.
