All Products
Search
Document Center

Simple Application Server:Network security

Last Updated:Jun 02, 2026

Simple Application Server secures network access through VPC isolation and built-in firewalls.

Use a VPC for private network isolation

Each Simple Application Server instance runs in an Alibaba Cloud VPC. Instances under the same account and region share a VPC and can communicate over the private network. However, they cannot communicate over the private network with other Alibaba Cloud services such as ECS instances and ApsaraDB databases.

Use a firewall to block attack traffic

Simple Application Server includes a built-in firewall that uses intrusion detection to inspect and filter traffic. By default, only ports 22, 80, and 443 are open, and all other ports are closed. Open additional ports as needed in Manage the firewall.

The firewall controls only the inbound traffic of a Simple Application Server instance. All outbound traffic is allowed by default.

Note
  • Inbound traffic: traffic flowing to an instance from the public network or a private network.

  • Outbound traffic: traffic flowing from an instance to a destination over the public network or internal network.