Firewall
What stands between your Tally data and the internet
Your cloud desktop has to be reachable from anywhere β that is the point of it β which means the server has an address on the public internet and strangers find it within hours of it existing. A firewall is what decides which of them gets to say anything to it at all. This page explains exactly what ours allows, what it blocks on its own, and what it deliberately does not try to do.
Only two doors, and both are watched
A server exposes software to the internet through ports. Most attacks start by finding one that should not have been open β a database left listening, a file share, an admin panel nobody remembered. The defence is not clever rules; it is having almost nothing open.
| Port | What it is for | Who may use it |
|---|---|---|
| 443 (HTTPS) | The web portal and your encrypted Remote Desktop session | Anyone β this is the way in |
| 80 (HTTP) | Redirects to HTTPS, and certificate renewal | Anyone, but it only redirects |
| Everything else | Database, file sharing, management API, administration | Blocked at the firewall. Not reachable from the internet at any address. |
The management interface that creates and changes accounts is not on this list because it is not exposed to the internet at all. Neither is the database your details sit in.
What gets blocked without anyone pressing a button
Watching a log and banning addresses by hand does not scale past the first week. Three rules run continuously instead, and each one exists because of a pattern we actually saw.
| What it watches for | What happens |
|---|---|
| Repeated failed logins against usernames that do not exist | Somebody guessing names rather than mistyping their own. The address is blocked automatically. |
| A burst of connections far above what a working office produces | Scanning or an attempt to exhaust the server. Blocked for 24 hours, then released β a mistake should not be permanent. |
| More than ten hits from outside India with no customer ever having signed in from there | Every customer is in India. An address that has never carried a real login and keeps knocking is blocked permanently. |
The last rule is deliberately narrow. It needs the address to be outside India, and to have never carried a successful customer login at any point in the past, and to keep trying. Any one of those being false and nothing happens.
The rule that protects you from the firewall
Automatic blocking has an obvious failure mode: it blocks a customer. An office with twenty people behind one internet connection can look like a burst of traffic, and being locked out of your own accounts during working hours is a worse outcome than almost anything the rule was built to stop.
- An address that any customer has signed in from is never blocked automatically β it is checked before every block, not after.
- Your office address can be whitelisted on request, after which nothing can block it at all, automatic or otherwise.
- If you are ever locked out, one message restores access immediately. We do not need you to prove anything first.
- Blocks are logged with the reason and the address, so there is always an answer to what happened and when.
What a firewall does not protect you from
This is the part most pages leave out. A firewall decides who may talk to the server. It has nothing to say about what happens once someone is allowed in, which is why it is one layer and not the answer.
| Risk | What actually handles it |
|---|---|
| Someone with a correct password signing in | A one-time password to the account owner's own WhatsApp number, required at every login. The password alone opens nothing. |
| One customer reaching another customer's files | File permissions on the server. Accounts are isolated by default and can only share inside the same company group. |
| Someone reading your session in transit | The session is SSL-encrypted end to end, which is what makes hotel and cafΓ© Wi-Fi safe to work from. |
| Your own staff member leaving with the password | You change it yourself from My Account, and sign-in history shows when and from which computer each person connected. |
| Ransomware on your own office PC | Nothing on the server side. Your data is not on that PC β which is the actual protection β and daily backups mean a bad day costs hours, not years. |
Want to check this against your own IT policy?
If your auditor or IT provider has specific questions about ports, blocking or access control, ask them directly β we would rather answer in detail before you commit than afterwards.
Prefer to talk? Call +91 92383 06670 or send the Airmax team an enquiry.