What is STACKIT Unified Firewall?
The STACKIT Unified Firewall (UFW) consolidates the security configuration of a STACKIT project into a central dashboard. Instead of managing access control lists and security groups spread across individual network resources, the Unified Firewall provides a single interface with a rule wizard, predefined templates, and an API-first architecture for automated security management. Scaling is handled automatically via a Kubernetes-based architecture.
Core Features
- Central security dashboard for all ACLs and security groups in a project
- Rule creation wizard with predefined templates for common scenarios
- API-first architecture with full CRUD operations
- Automated scaling for growing traffic volumes and more complex rule sets
- Compatibility with existing ACL workflows
Typical Use Cases
Central Security Management: Teams manage all firewall rules for a project through a single dashboard instead of scattered individual configurations on each resource.
Automated Security Pipelines: The API allows firewall rules to be integrated into CI/CD pipelines or infrastructure-as-code workflows.
Onboarding for Teams Without Dedicated Security Specialists: The rule wizard with templates makes it easier for development teams to configure secure baseline rules.
Benefits
- Free to use, automatically active when a project is created
- Central instead of decentralized rule management
- API-first for automation
- Operated in German data centers
Integration with innFactory
As an official STACKIT partner, innFactory supports you with network security architecture: from firewall rule design and segmentation design to automation via the Unified Firewall API.
Typical Use Cases
Frequently Asked Questions
What is STACKIT Unified Firewall?
The STACKIT Unified Firewall (UFW) is a central security dashboard that consolidates the firewall configuration (access control lists, security groups) of a STACKIT project in one place instead of spreading it across individual resources.
What does the Unified Firewall cost?
The Unified Firewall is currently offered as a free service and is automatically active when a project is created.
Does the Unified Firewall offer intrusion detection/prevention (IDS/IPS)?
No, the current release focuses on central ACL and security group management. Traffic inspection features such as IDS/IPS, geo-blocking, and URL filtering have been announced for a future next-generation firewall extension but are not yet available.
Can I automate the firewall via API?
Yes, the Unified Firewall is built on an API-first architecture with full CRUD operations, so rules can be managed in an automated way.
Do existing ACL workflows still work?
Yes, existing workflows for creating, updating, and deleting access control lists continue to work alongside the new Unified Firewall interface.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.
