Tutorials Cloud Computing Tutorial
Firewalls — Complete Guide
Firewalls — Complete Guide: free step-by-step lesson with examples, common mistakes, and interview tips — part of Cloud Computing Tutorial on Toolliyo Academy.
On this page
Cloud Computing Tutorial · Lesson 15 of 100
Firewalls
Foundations → Platform → Ops → Projects
Foundations · 1 — Cloud & networks · ~6 min · Cloud — Networking & Infrastructure
What is this?
Cloud firewalls/security groups/NSGs control allowed ports and sources at instance or subnet level.
Why should you care?
CloudVerse default deny: only open what the architecture needs.
See it live — copy this example
Use AWS/Azure/GCP free tier or local Docker/Kind. Sketches and YAML are meant to be typed and adapted.
# SG rules (app tier)
# inbound 8080 from LB SG only
# outbound 443 to 0.0.0.0/0 (updates) — tighten later
# DB SG: 5432 from app SG only
What happened?
- Prefer SG references over wide CIDRs.
- Network ACLs are coarser; use both thoughtfully.
Practice next
- Lock DB to app SG.
- Remove 0.0.0.0/0 on SSH.
- Use bastion or SSM.
- Add ephemeral port notes.
- Export SG rules to IaC.
Remember
Default deny. SG-to-SG. No public SSH.
CloudVerse SG baseline
DB only from app SG.
Outcome: Port scan from internet fails.
Interview prep for this lesson
Practice these questions aloud after reading—each links to a full structured answer.
Sign in to ask a question or upvote helpful answers.
No questions yet — be the first to ask!