Skip to main content
Cloud / STACKIT / Products / STACKIT Network Security - Firewall & Security Groups

STACKIT Network Security - Firewall & Security Groups

STACKIT Network Security: Security Groups, Unified Firewall, and STACKIT Network Area from Germany. GDPR-compliant.

Network
Pricing Model Security groups and networking included with infrastructure resources; Unified Firewall currently free (beta)
Availability STACKIT regions in Germany and Austria
Data Sovereignty Traffic stays in German/European data centers
Reliability SLA as published by the provider SLA

What is STACKIT Network Security?

STACKIT Network Security bundles the security features around STACKIT networks: security groups acting as stateful host firewalls for individual instances, the central Unified Firewall for cross-project management, and connectivity options via STACKIT Network Area (SNA) and VPN for hybrid scenarios. STACKIT operates the underlying infrastructure from data centers in Germany and Austria.

Core Features

  • Security Groups: Stateful firewall rules per instance, reusable across multiple servers; the default rule blocks inbound traffic until explicitly allowed
  • Unified Firewall (beta): Central dashboard that combines security groups, database ACLs, and public IP rules across projects, including a rule wizard with templates
  • STACKIT Network Area (SNA): Private transfer network connecting multiple projects within an organization at the network level, without traversing the public internet
  • VPN connectivity: IPsec-based VPN appliance (strongSwan) securely connects on-premises sites to the STACKIT Network Area
  • API-first: Manage security groups and firewall rules via API, CLI, and the Terraform provider

Typical Use Cases

Multi-tier architectures: Web, application, and database tiers are isolated from each other via separate security groups.

Microservices networking: Kubernetes workloads on STACKIT Kubernetes Engine use security groups and network segmentation to secure traffic between services.

Hybrid cloud connectivity: On-premises data centers securely connect to the STACKIT Network Area via an IPsec VPN appliance.

Central security management: Teams with multiple STACKIT projects use the Unified Firewall to manage security rules in one place instead of per project.

Benefits

  • Data sovereignty: Network traffic stays in German/European data centers
  • Stateful security groups: Included in infrastructure resource pricing
  • Central visibility: Unified Firewall reduces operational complexity across multiple projects
  • GDPR-compliant: Operated without US-CLOUD Act risk

Integration with innFactory

As an official STACKIT partner, innFactory supports you with network and security architecture: segmentation concepts using security groups, building STACKIT Network Area and VPN connections, and rolling out the Unified Firewall for central security management.

Available Tiers & Options

Unified Firewall (beta)

Strengths
  • Central dashboard for security groups, ACLs, and public IPs
  • Rule wizard with templates
  • Currently free
Considerations
  • Beta status, feature set still growing

Typical Use Cases

Multi-tier application isolation
Microservices networking
Hybrid cloud connectivity via VPN
Central security management across multiple projects

Frequently Asked Questions

What is STACKIT Network Security?

Network Security bundles the security services around STACKIT networks: security groups acting as host firewalls, the central Unified Firewall dashboard, and connectivity options via STACKIT Network Area (SNA) and VPN.

Are security groups stateful?

Yes, security groups track connection state and automatically allow return traffic without separate rules. By default, all outbound traffic is allowed and inbound traffic must be explicitly permitted.

What is the STACKIT Unified Firewall?

The Unified Firewall (currently in beta) combines security groups, database ACLs, and public IP rules into a central dashboard across multiple projects. It is currently free to use.

How do I connect multiple STACKIT projects or on-premises networks?

STACKIT Network Area (SNA) connects multiple projects via a private transfer network. For hybrid scenarios, on-premises infrastructure can be securely connected to the SNA via an IPsec VPN appliance.

Is DDoS protection available?

STACKIT offers integrated DDoS protection primarily for anycast DNS as part of its Domains, DNS & SSL services. For individual compute resources, a combination of security groups, Unified Firewall, and architectural measures is recommended.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.

STACKIT Partner

innFactory is an official STACKIT Partner. We provide consulting, implementation, and managed services for the sovereign cloud.

STACKIT Official Partner

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

AWS

Amazon API Gateway - Managed API Platform

Amazon API Gateway is a fully managed service for creating, publishing, and managing REST, HTTP, and WebSocket APIs.

Pricing Pay per request (tiered by volume), plus …
SLA SLA as published by the provider
Compare →
AWS

Amazon CloudFront: Content Delivery Network

Amazon CloudFront is AWS's global CDN with 750+ Points of Presence for fast content delivery worldwide.

Pricing Pay-as-you-go (data transfer and …
SLA 99.9% Monthly Uptime Percentage per official SLA
Compare →
AWS

Amazon Route 53 - DNS and Domain Registration

Amazon Route 53 is AWS' scalable DNS service for domain registration, routing, and health checks.

Pricing Pay per hosted zone and per DNS query, …
SLA SLA as published by the provider: tiered service credits when monthly availability falls below 99.99% (see official SLA page)
Compare →
AWS

Amazon Route 53 Global Resolver - Hybrid DNS

Amazon Route 53 Global Resolver: internet-reachable anycast DNS resolver for secure DNS resolution across branch, remote …

Pricing Hourly per-region fee + pay-per-query
SLA N/A
Compare →
AWS

Amazon VPC - AWS Networking & Content Delivery Service

Amazon VPC is an AWS service for Network isolation and Multi-tier web applications. GDPR-compliant in EU regions.

Pricing No charge for the VPC itself, pay only …
SLA N/A (free base service; components like NAT Gateway have their own SLAs)
Compare →
AWS

Amazon VPC Lattice - Application Networking

Amazon VPC Lattice simplifies service-to-service communication. Consistent application networking across VPCs and …

Pricing Pay-per-use: hourly per service plus per …
SLA SLA as published by the provider
Compare →

57 comparable products found across other clouds.

Ready to start with STACKIT Network Security - Firewall & Security Groups?

Our certified STACKIT experts help you with architecture, integration, and optimization.

Schedule Consultation