Skip to content

Firewall

What stands between your Tally data and the internet

Your cloud desktop has to be reachable from anywhere β€” that is the point of it β€” which means the server has an address on the public internet and strangers find it within hours of it existing. A firewall is what decides which of them gets to say anything to it at all. This page explains exactly what ours allows, what it blocks on its own, and what it deliberately does not try to do.

Only two doors, and both are watched

A server exposes software to the internet through ports. Most attacks start by finding one that should not have been open β€” a database left listening, a file share, an admin panel nobody remembered. The defence is not clever rules; it is having almost nothing open.

What the firewall allows
PortWhat it is forWho may use it
443 (HTTPS)The web portal and your encrypted Remote Desktop sessionAnyone β€” this is the way in
80 (HTTP)Redirects to HTTPS, and certificate renewalAnyone, but it only redirects
Everything elseDatabase, file sharing, management API, administrationBlocked at the firewall. Not reachable from the internet at any address.

The management interface that creates and changes accounts is not on this list because it is not exposed to the internet at all. Neither is the database your details sit in.

What gets blocked without anyone pressing a button

Watching a log and banning addresses by hand does not scale past the first week. Three rules run continuously instead, and each one exists because of a pattern we actually saw.

Automatic blocking rules
What it watches forWhat happens
Repeated failed logins against usernames that do not existSomebody guessing names rather than mistyping their own. The address is blocked automatically.
A burst of connections far above what a working office producesScanning or an attempt to exhaust the server. Blocked for 24 hours, then released β€” a mistake should not be permanent.
More than ten hits from outside India with no customer ever having signed in from thereEvery customer is in India. An address that has never carried a real login and keeps knocking is blocked permanently.

The last rule is deliberately narrow. It needs the address to be outside India, and to have never carried a successful customer login at any point in the past, and to keep trying. Any one of those being false and nothing happens.

The rule that protects you from the firewall

Automatic blocking has an obvious failure mode: it blocks a customer. An office with twenty people behind one internet connection can look like a burst of traffic, and being locked out of your own accounts during working hours is a worse outcome than almost anything the rule was built to stop.

  • An address that any customer has signed in from is never blocked automatically β€” it is checked before every block, not after.
  • Your office address can be whitelisted on request, after which nothing can block it at all, automatic or otherwise.
  • If you are ever locked out, one message restores access immediately. We do not need you to prove anything first.
  • Blocks are logged with the reason and the address, so there is always an answer to what happened and when.

What a firewall does not protect you from

This is the part most pages leave out. A firewall decides who may talk to the server. It has nothing to say about what happens once someone is allowed in, which is why it is one layer and not the answer.

Outside the firewall's job
RiskWhat actually handles it
Someone with a correct password signing inA one-time password to the account owner's own WhatsApp number, required at every login. The password alone opens nothing.
One customer reaching another customer's filesFile permissions on the server. Accounts are isolated by default and can only share inside the same company group.
Someone reading your session in transitThe session is SSL-encrypted end to end, which is what makes hotel and cafΓ© Wi-Fi safe to work from.
Your own staff member leaving with the passwordYou change it yourself from My Account, and sign-in history shows when and from which computer each person connected.
Ransomware on your own office PCNothing on the server side. Your data is not on that PC β€” which is the actual protection β€” and daily backups mean a bad day costs hours, not years.

Want to check this against your own IT policy?

If your auditor or IT provider has specific questions about ports, blocking or access control, ask them directly β€” we would rather answer in detail before you commit than afterwards.

Prefer to talk? Call +91 92383 06670 or send the Airmax team an enquiry.