Skip to main content
Use • 2 mins read

Public IPv4 and Firewall

Public IPv4 and Firewall

A new VM is only reachable on your private network. This page shows how to open it to the internet safely: attach a public IPv4 address, allow only the traffic you need with firewall rules, or publish a single web service on an HTTPS address.

Everything here is on the VM's page, on the Dashboard tab, in the Public IP & Firewall panel.

How a VM is reached​

  • Private network. Every VM joins your account's private network at first boot. Your VMs and managed services reach each other there.
  • Public IPv4. An optional, dedicated address for one VM. Inbound traffic to it is blocked except what your firewall rules allow.
  • Published ports. An HTTPS address on a Hippius domain that forwards to one port of your VM. Useful for a web service when you don't need a whole public address.
  • Browser terminal. The VM page's Console tab gives you a shell without any public address. See Connect from the browser.

Attach a public IPv4​

You can add a public IPv4 when you create the VM (the Public IPv4 add-on), or later:

  1. Open the VM's page. The VM must be running.
  2. In Public IP & Firewall, click Attach public IPv4.
  3. The dialog tells you which firewall rules will apply at once and what the address costs. Click Attach.

The address is dedicated to your VM. Inbound and outbound traffic both use it: once it is attached, the VM's outgoing connections leave from this address too. It counts against your Public IPv4 quota, and the 24-hour balance requirement applies.

If no address is free, the console says so. Try again later, or launch without one.

The address is not on the VM's network interface

You won't see the public address with ip addr inside the VM. To print it from inside the VM, run:

curl http://169.254.169.254/metadata/public-ip

Bind your services to 0.0.0.0 (all interfaces), not to a specific address, so they answer traffic that arrives through the public IPv4.

What a public IPv4 costs​

A public IPv4 costs $0.005 an hour (about $3.65 a month), billed per second while it is attached, with a minimum of one minute. The Attach dialog shows its price. The current price is also in the live price list. Public bandwidth is free for now.

Detach an address​

Click Detach in Public IP & Firewall and confirm. The address stops reaching your VM and goes back to the pool: you may not get it back. Outbound traffic leaves from the host's address again.

Your firewall rules are kept. They apply again as soon as you attach a new address. Deleting the VM releases its address too.

Firewall rules​

The firewall protects the VM's public IPv4. It works like this:

  • All inbound traffic is blocked by default. Each rule allows something. There are no "deny" rules.
  • Outbound traffic is open, except SMTP. Outbound SMTP (port 25) is blocked by default; to send mail, open a support ticket to have it allowed on a public IPv4 address.
  • Ping (ICMP) and replies to connections the VM opened always get through. You don't need a rule for them.
  • IPv4 only. Sources are IPv4 addresses or ranges.

You can write rules before an address is attached. They are kept, and enforced as soon as one is.

Add a rule​

  1. In the Inbound firewall section, click Add rule.
  2. Choose the Protocol: TCP, UDP or ICMP.
  3. Under Ports, type a port (443) or a range (8000-8080) and press Enter. Add as many as you need. Leave it empty to match every port. ICMP rules take no ports.
  4. Under Sources, add the IPv4 addresses or ranges allowed, for example 203.0.113.7 or 203.0.113.0/24. Leave it empty to allow any source.
  5. Optionally add a Description, up to 128 characters.
  6. Click Save rule.

Untick Enabled to keep a rule without enforcing it. Each rule can be edited or deleted from the rules table.

A change reaches the network edge within about 15 seconds. The panel shows Applying to the edge… and then Live on the edge once the change is confirmed.

Write ranges correctly

A range must start on its network boundary: 203.0.113.0/24 is valid, 203.0.113.7/24 is not. The console suggests the right value when you get it wrong. A single address is saved as /32.

Limits​

LimitValue
Rules per VM50
Ports or ranges per rule20
Sources per rule20
Port numbers1 to 65535

If someone else changes the rules while you edit them, saving is refused with The rules changed since you loaded them. Reload the page and make your change again.

Restrict SSH to your own address​

If you launched the VM with Open SSH (port 22) to the internet, it has a rule named SSH (opened at launch): TCP, port 22, from any source. Anyone on the internet can then try to log in. Logins still need your SSH key, but you can close the door to everyone else:

  1. Find your public address. Searching "what is my IP" in a browser shows it.
  2. In Inbound firewall, edit the rule SSH (opened at launch).
  3. Under Sources, add your address, for example 203.0.113.7. Add any other addresses you connect from.
  4. Click Save rule.

To close SSH completely, delete the rule, or untick Enabled. You can still open a shell from the browser with the Console tab.

If you attach an address later, no SSH rule is created for you. Add one yourself, with your own address as the source.

If inbound traffic doesn't arrive​

If the panel says Inbound traffic to this IP is blocked inside the VM, a small agent inside the VM that lets public traffic through the VM's own private-network firewall isn't running. VMs created before 24 September 2026 don't have it. Outbound traffic still works.

The panel's How to fix it steps tell you what to install, if anything. If the agent is installed but stopped, start it and keep it across reboots:

sudo systemctl daemon-reload && sudo systemctl enable --now hippius-public-ip-inbound.timer

If it still shows after a minute, contact support.

Publish a web service on an HTTPS address​

If you want to share one web service without a public IPv4, publish its port:

  1. On the VM's page, find Published ports.
  2. Click Publish a port, enter the port your service listens on inside the VM, for example 8080, and click Publish.
  3. The panel shows an address like https://NAME.hpcr.io that forwards to that port.

Your service should speak plain HTTP on that port: the Hippius edge handles HTTPS for you. Port 22 can't be published; use the browser terminal for SSH. To unpublish it, click the remove button next to the address.

The edge can read published traffic

The Hippius edge terminates TLS for published ports. Traffic is encrypted on every wire (HTTPS to the edge, then your private network to the VM), but it is not end-to-end. Don't publish anything only you should be able to read. Use a public IPv4 with your own TLS for that.

Applications such as WordPress publish their port for you once they are up.

Your private network​

Every VM, database and Kubernetes node joins your account's private network. The Copy Overlay IP button on a VM's page gives its address on that network.

Use it to connect your machines to each other without going through the internet, for example an application VM to a managed PostgreSQL database. Traffic between them stays on the encrypted private network.

GitHub Actions runner VMs are never added to your private network, so a workflow can't reach your other machines.