Skip to content
  • GDPR-compliant
  • 100% hosting in Germany
  • Personal contact
  • Support included
  • Provisioning within 24 hours
Reachability & networks 3 min read

Networks and firewall: connecting containers and controlling outbound connections

The Network tab of your project has three sections: who can access your containers from outside, which containers communicate with one another, and where your containers are permitted to establish connections.

01 · From outside

Here you can see all containers with their web addresses and ports, access protection settings and the status of your own domains, such as ‘Waiting for DNS’. Change takes you to the container’s reachability settings (Making a container reachable on the web). Below this, you’ll see how many custom ports and domains your plan allows.

The ‘From outside’ section with the addresses and reachability of all containers
From outside: WordPress is reachable on the web, while MariaDB and Valkey are only accessible within the project.

02 · Between containers: networks

Every project has the network standard with internet access. Containers on the same network can be reached via their name, for example mariadb:3306. The platform assigns new internal IP addresses on every start - so always use the name.

To create your own network:

  1. Click on Create network. Next to this, you’ll see how many networks your plan allows.
  2. Enter a name, for example datenbank.
  3. Choose the internet access: Internal only or With internet.
  4. The subnet is optional - if you do not specify one, the platform will select one for you.
  5. Click on Create network.
Project networks with an internal ‘database’ network and the form for creating a network
The internal ‘database’ network, which is not connected to the internet, and the form for another network.

Assigning a container to a network: open the container and, in the Settings tab under ‘Data, networks and start’, select the networks you want. Save - the container will be recreated in the process. A container can be part of several networks. A typical example is:

  • wordpress in standard (with internet access, e.g. for updates) and in datenbank
  • mariadb and valkey only in datenbank (internal, without internet)

Without a network, a container cannot access other containers or the internet.

Databases belong on an internal network

An internal network has no connection to the internet. A database on that network is accessible only to containers on the same network and cannot establish connections to the outside world itself. This protects your data even if another part of your application is attacked.

03 · To the outside: outbound rules

Here you can specify where your containers are permitted to establish connections:

  • Allow everything (default) - all destinations are permitted. You can block individual destinations using rules.
  • Allowed destinations only - everything is blocked except the destinations you allow. This is the most secure setting if you know exactly which services your application requires.

A rule consists of a destination (IP address or network, for example 198.51.100.0/24), port (blank means all ports), protocol (TCP, UDP or All), action (Allow or Block) and a comment. Add rules using Add rule and click Save.

Outbound rules with mode, exceptions and a note on the fixed platform rules
Outbound rules: exceptions for a payment service and a mail server.

Fixed platform rules

Regardless of your own rules, the following fixed platform rules apply: no sending via port 25, no access to the platform’s internal networks, and no connection to other projects. Your applications send email via your provider’s mail server with authentication, usually via port 587 or 465.

Why can’t my container send emails via port 25?
Port 25 is blocked to protect against spam. Please use your email provider’s mail server, with authentication via port 587 or 465.
Can containers from different projects communicate with one another?
No. Projects are strictly separate from one another. If two applications require a direct connection, create them within the same project.
How does WordPress access my database?
Both containers must be on the same network. Enter the name of the database container in WORDPRESS_DB_HOST, for example mariadb.

Was this article helpful?

New to SpeedIT Solutions?

Hosting where you know someone.

What you are reading here is what we put into practice for our customers every day. Based in Isernhagen since 2009 - with dedicated contact persons rather than a call centre.

  • 100% hosted in Germany
  • GDPR-compliant
  • Dedicated contact person
  • Provisioning within 24 hours
4.9 88 reviews on Expeero

Top Preis-Leistungsverhältnis

Hab schon Erfahrung mit anderen Hostern z.Bspl.: S...... SpeedIT S hat für mich als privater nutzer das beste Preis-Leistungsverhältnis. Der Kunden-Service bzw Support reagiert innerhalb kürzester Zeit. Sehr übersichtliches Dashboard.
HD S. G.Recommends us · 08/07/2026

100 % recommend us · Expeero

All reviews on HOSTtest (opens in a new window)

You might also be interested in:

Personal support

Of course, our support team is also happy to assist you personally. If you cannot find what you are looking for in our knowledge base or require personalised support, please do not hesitate to contact us. We’re here to help you and to ensure that your experience with our products and services is as smooth and enjoyable as possible.