Skip to main content
Cloud / STACKIT / Products / STACKIT Unified Firewall - Central Network Security

STACKIT Unified Firewall - Central Network Security

STACKIT Unified Firewall (UFW): central management of access control lists and security groups for STACKIT projects, free of charge.

Network
Pricing Model Included free of charge (free tier)
Availability STACKIT regions EU01 (Germany) and EU02 (Austria)
Data Sovereignty Operated in German data centers
Reliability SLA as published by the provider SLA

What is STACKIT Unified Firewall?

The STACKIT Unified Firewall (UFW) consolidates the security configuration of a STACKIT project into a central dashboard. Instead of managing access control lists and security groups spread across individual network resources, the Unified Firewall provides a single interface with a rule wizard, predefined templates, and an API-first architecture for automated security management. Scaling is handled automatically via a Kubernetes-based architecture. STACKIT’s release notes confirmed general availability (GA) on project level as of July 7, 2026 (“STACKIT Unified Firewall is now Generally Available”), including EU02 region support, project-level rule export, RBAC, and free-tier access. A navigation badge in parts of the documentation still shows the outdated “Beta” label; we classify the service as GA based on the dated, feature-specific GA confirmation in the release notes. UFW is offered in the EU02 region in addition to EU01.

Core Features

  • Central security dashboard for all ACLs and security groups in a project
  • Rule creation wizard with predefined templates for common scenarios
  • API-first architecture with full CRUD operations
  • Automated scaling for growing traffic volumes and more complex rule sets
  • Project-level rule export for security audits and compliance reporting
  • Built-in role-based access control (RBAC) for strict enforcement of user permissions
  • Available in the EU01 (Germany) and EU02 (Austria) regions
  • Compatibility with existing ACL workflows

Typical Use Cases

Central Security Management: Teams manage all firewall rules for a project through a single dashboard instead of scattered individual configurations on each resource.

Automated Security Pipelines: The API allows firewall rules to be integrated into CI/CD pipelines or infrastructure-as-code workflows.

Onboarding for Teams Without Dedicated Security Specialists: The rule wizard with templates makes it easier for development teams to configure secure baseline rules.

Benefits

  • Free to use, automatically active when a project is created
  • Central instead of decentralized rule management
  • API-first for automation
  • Operated in the STACKIT regions EU01 and EU02

Integration with innFactory

As an official STACKIT partner, innFactory supports you with network security architecture: from firewall rule design and segmentation design to automation via the Unified Firewall API.

Typical Use Cases

Central management of access control lists (ACLs)
Managing security groups through a unified dashboard
Rule creation via wizard with predefined templates
Automated firewall management via API
Exporting a project's firewall rules for audits and compliance reporting

Frequently Asked Questions

What is STACKIT Unified Firewall?

The STACKIT Unified Firewall (UFW) is a central security dashboard that consolidates the firewall configuration (access control lists, public IPs, security groups) of a STACKIT project in one place instead of spreading it across individual resources. STACKIT's release notes dated July 7, 2026 confirm general availability (GA) on project level ("STACKIT Unified Firewall is now Generally Available"), including EU02 region support, project-level rule export, RBAC, and free-tier access — concrete, already-usable features, not just an announcement. A navigation badge in parts of the documentation still shows the outdated "Beta" label; the dated, feature-specific GA confirmation in the release notes is authoritative for our classification. UFW is offered in the EU01 and EU02 regions.

What does the Unified Firewall cost?

The Unified Firewall is currently offered as a free service and is automatically active when a project is created.

Does the Unified Firewall offer intrusion detection/prevention (IDS/IPS)?

No, the current release focuses on central ACL and security group management. Traffic inspection features such as IDS/IPS, geo-blocking, and URL filtering have been announced for a future next-generation firewall extension but are not yet available.

Can I automate the firewall via API?

Yes, the Unified Firewall is built on an API-first architecture with full CRUD operations, so rules can be managed in an automated way.

Do existing ACL workflows still work?

Yes, existing workflows for creating, updating, and deleting access control lists continue to work alongside the new Unified Firewall interface.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.

STACKIT Partner

innFactory is an official STACKIT Partner. We provide consulting, implementation, and managed services for the sovereign cloud.

STACKIT Official Partner

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

Google Cloud

Certificate Manager - Central TLS Certificate Management

Certificate Manager acquires, manages, and deploys TLS certificates for Cloud Load Balancing, Secure Web Proxy, and …

Pricing Pricing as published on the official …
SLA SLA as published by the provider
Compare →
Google Cloud

Cloud Domains - Domain Registration in Google Cloud

Cloud Domains lets you register and manage domains directly in Google Cloud, with billing through Cloud Billing and …

Pricing Per top-level domain pricing as …
SLA SLA as published by the provider
Compare →
Google Cloud

Data Transfer Essentials - Data Transfer Between Cloud Providers

Data Transfer Essentials provides cost-optimized data transfer between the services of an application that resides …

Pricing Currently offered at no charge when used …
SLA SLA as published by the provider
Compare →
Google Cloud

Secure Access Connect - Attach SSE Services to NCC Gateway

Secure Access Connect lets you connect security service edge products to NCC Gateway for security processing and secure …

Pricing Billed according to NCC Gateway pricing …
SLA SLA as published by the provider
Compare →
Google Cloud

Service Extensions - Custom Code in the Network Data Path

Service Extensions inserts custom code into the data path of Cloud Load Balancing, Media CDN, and Secure Web Proxy, as …

Pricing Billed per invocation: plugins on Cloud …
SLA As published by the provider / see official documentation
Compare →
Google Cloud

Telecom Network Automation - Cloud-Native Automation for Telecom Networks

Telecom Network Automation is Google's managed cloud implementation of the open source Nephio project for intent-driven …

Pricing Pay-as-you-go per automated vCPU per …
SLA SLA per provider / see official documentation
Compare →

70 comparable products found across other clouds.

Ready to start with STACKIT Unified Firewall - Central Network Security?

Our certified STACKIT experts help you with architecture, integration, and optimization.

Schedule Consultation