Introduction
The RCS Firewall is a web-based firewall to protect your cloud servers. The RCS Load Balancer is a fully-managed solution to distribute traffic across multiple back-end servers. In this guide, you'll learn how to use them together. You'll distribute web traffic with a Load Balancer while protecting the web servers with the RCS Firewall. If you are new to RCS Load Balancers, we recommend reading the Load Balancer Quickstart Guide first. You can also learn more in our RCS Firewall Quickstart Guide.
In this guide, you'll configure the RCS Firewall to accept traffic from a RCS Load Balancer, as shown below.
When configured this way, the RCS Firewall only accepts traffic from the Load Balancer, preventing direct connections to the web servers if users try to bypass the load balancer. Here's a step-by-step guide to creating a secure, load-balanced web cluster behind the RCS Firewall.
1. Deploy Web Servers and Load Balancer
Deploy three web servers in a single location.
Navigate to the Load Balancers section of the RCS Customer Portal.
Click the blue plus icon to deploy a load balancer.
Choose the same location as your web servers.
In Load Balancer Configuration, enter a label and leave the other options at default.
Leave the default Forwarding Rule for HTTP at port 80.
Choose Public in the Private Network section.
Do not add any Firewall Rules. The firewall rules in this section are for the Load Balancer Firewall, which is different than the RCS Firewall. See our article How to Use the RCS Load Balancer Firewall to learn more.
Choose HTTP and Port 80 for Health Checks.
Click Add Load Balancer.
Wait for the Load Balancer to deploy.
2. Link the Load Balancer to the Web Servers
Click your Load Balancer to edit its configuration.
Note the URL of this page. The Load Balancer ID is at the end of the query string.
For example, if your URL is:
https://my.rcs.is/loadbalancers/manage/?id=11111111-0000-ffff-2222-333444555666
Then, your Load Balancer ID is
11111111-0000-ffff-2222-333444555666
. Note this value. You'll need it when configuring the Vutr Firewall.Add your instances: Click Add Instance.
Choose an instance from the drop-down.
Click Attach Instance.
Repeat steps 3 – 5 for each web server instance.
3. Deploy a RCS Firewall
Navigate to the Add Firewall Group page.
Give the firewall group a descriptive name and click Add Firewall Group.
Add an inbound IPv4 Rule that accepts HTTP from the Load Balancer source, indicated by
1
in the screenshot below. Enter the Load Balancer ID you noted earlier, indicated by2
.Click Linked Instances on the left menu.
Link each of the three instances to the firewall group.
Conclusion
By linking the Firewall HTTP rule to the Load Balancer source, you've prevented direct access to the web servers. All HTTP traffic to the web servers must travel through the Load Balancer.
You may want to add more rules to the RCS Firewall to allow HTTPS for a production environment. You may also want to allow SSH with your IP address as the source.
Advanced Configuration
In this article, you've explored the RCS Firewall. Load Balancers also have their own internal firewall rules, and you can combine these for an advanced configuration as shown below.
In this example, the Load Balancer Firewall accepts traffic from Cloudflare IPs, while the RCS Firewall accepts traffic from the Load Balancer. All other traffic to the web servers is denied.
You can learn more about the Load Balancer Firewall in our article, How to Use the RCS Load Balancer Firewall.
More Information
If you are new to load-balancing network concepts, see the RCS Load Balancer Quickstart Guide.
For comprehensive documentation about the Load Balancer features, see the Load Balancer Feature Reference.
The RCS Load Balancer has an integrated firewall; learn more in our article How to Use the RCS Load Balancer Firewall.
Explore an advanced scenario with private networking and both types of firewalls in How to Configure a RCS Load Balancer with Private Networking.
Learn how to configure wildcard SSL on your load balancer in our guide Use a Wildcard Let's Encrypt Certificate with RCS Load Balancer.