Hetzner Cloud egress control

Managed egress control for Hetzner Cloud, and the SOC 2 evidence.

Hetzner's Cloud Firewall is free and stateful, but IP and port only — no FQDN, no L7 — and there is no managed NAT. Move a production SaaS to Hetzner and a SOC 2 or ISO 27001 review asks you to control and prove outbound access by destination. Enforza gives managed, domain-aware egress control and audit-ready logs to your own SIEM, on a server in your Hetzner network, without building or maintaining your own gateway.

The gap

Free, stateful, IP-and-port only

To be fair: Hetzner's Cloud Firewall is a good, free, stateful firewall, and outbound rules are now supported. The gap is domain-awareness and an audit trail — and the absence of a managed NAT to route through.

Hetzner Cloud Firewall
  • Free, stateful; inbound and outbound rules
  • TCP, UDP, ICMP, ESP, GRE — matched by IP and port
  • Limits: 5 firewalls per server, 500 rules per firewall
  • No FQDN, no SNI, no L7 anywhere
  • No managed NAT — the native answer is a DIY tutorial
Enforza adds
  • FQDN/SNI-based egress control, without breaking TLS
  • Secure source NAT and stateful L3/L4 in one managed appliance
  • Audit-ready outbound logs to your own SIEM, by destination
  • Advise-or-enforce compliance on publish — 25 frameworks / 210 controls
  • Managed lifecycle and one console across your servers
The compliance moment

Auditable outbound control for SOC 2 CC6.1

Hetzner's data centres carry ISO 27001, but not SOC 2 — so when a customer security review or a SOC 2 audit lands, controlling and evidencing outbound access is on you. Free IP/port rules and a hand-rolled gateway do not produce a destination-level audit trail. This is the one place Enforza earns its keep on Hetzner.

Control egress by destination

Allow the destinations you trust by name and deny the rest with FQDN and SNI rules that never decrypt TLS or hold your keys — the outbound control CC6.1 expects.

Prove it with audit-ready logs

Outbound logs stream to your own SIEM, never via Enforza's cloud, giving auditors a destination-level record of what left your Hetzner servers.

Managed, not a free afternoon

The DIY route is genuinely free; what it lacks is managed lifecycle, centralised policy and an audit trail. Enforza is those three — self-patching, self-upgrading, one console across your servers.

Deploy

How it deploys on Hetzner Cloud

It installs on a Hetzner Cloud server with a registration key. One Hetzner specific is worth knowing: the route lives on the network object, not the server.

  1. Install on a server

    A single Linux VM in your own Hetzner Cloud network, any server type. Install with a registration key — cloud-init is supported — and it registers to the Enforza cloud over an outbound connection and pulls its policy.

  2. Route via the network object

    Add a 0.0.0.0/0 route on the network object with the Enforza server's private IP as the target — this lives on the network, not the instance, which is the common trip-up — and enable IP forwarding on the server.

  3. Filter and log

    Enforza does secure source NAT, applies your FQDN/SNI egress policy, and streams outbound logs to your SIEM. Turn on advise-or-enforce compliance checks whenever a review demands the evidence.

FAQ

Hetzner Cloud egress firewall — common questions

What does the Hetzner Cloud Firewall do?

It is a genuinely useful, free, stateful firewall. It now supports outbound rules as well as inbound, over TCP, UDP, ICMP, ESP and GRE, matched by IP and port. The limits are five firewalls per server and 500 rules per firewall. What it does not do — anywhere — is FQDN, SNI or L7: there is no way to allow or deny outbound traffic by destination name. For IP and port control it is solid; for domain-aware, auditable egress it stops short.

Can the Hetzner Cloud Firewall filter outbound traffic by domain?

No. It matches on IP and port only. If a security review or a SOC 2 control needs you to allow specific destinations by name and deny the rest — and to prove what left by destination — the native firewall cannot express that. Enforza adds FQDN/SNI-based egress control and destination-level logging on a server in your own Hetzner network.

Does Hetzner have a managed NAT gateway?

No. Hetzner does not offer a managed NAT product; its own guidance is a do-it-yourself tutorial for setting up NAT on a cloud server. That is honest to acknowledge — and it is also the point. You can build and maintain your own gateway for free, or you can run Enforza as a managed appliance that does secure source NAT, FQDN/SNI egress filtering and audit-ready logging, and keeps itself patched and up to date.

How does Enforza help with SOC 2 CC6.1 on Hetzner?

SOC 2 CC6.1 expects outbound access to be controlled and auditable by destination. Hetzner's data centres carry ISO 27001 but not SOC 2, so that control falls on you, the application owner — and free IP/port rules plus a hand-rolled gateway do not produce a destination-level audit trail. Enforza gives you FQDN/SNI-based egress policy and streams outbound logs to your own SIEM, so you have the evidence a security review asks for, with advise-or-enforce checks across 25 framework packs and 210 firewall-applicable controls.

Isn't the DIY approach on Hetzner free?

Yes — and we will not pretend otherwise. Hetzner's free Cloud Firewall plus a self-built gateway following Hetzner's own tutorial costs nothing but your time. What you do not get from that is a managed lifecycle, centralised policy across your servers, or audit-ready egress logs by destination. Enforza's value here is exactly those three things — managed, centralised and auditable — not a lower price. If a free afternoon and ongoing maintenance suit you, that is a fair choice.

How does Enforza route on Hetzner Cloud?

You install Enforza on a Hetzner Cloud server of any type with a registration key. The route to send workload egress through it lives on the network object — a 0.0.0.0/0 route with the Enforza server's private IP as the target, which is a common trip-up because it is not set on the instance — and you enable IP forwarding on the server. Enforza then does secure source NAT and applies your egress policy. Hetzner private networks do not reverse-path-filter, so there is no anti-spoofing toggle to disable; cloud-init is supported for automated setup.

Is there a free way to try it?

Yes. Enforza has a genuine free tier — one firewall with L3/L4 policy and network objects, no card required — and a 14-day trial that unlocks the full feature set, including FQDN/SNI-based L7 filtering, compliance packs, log export and live logs. See the pricing page for the plan details.

Auditable, domain-aware egress for Hetzner Cloud.

Give your Hetzner servers outbound control a review will accept.

Managed FQDN/SNI-based egress control, secure NAT and audit-ready logs on a server in your own Hetzner network — the destination-level evidence SOC 2 CC6.1 asks for, without building or maintaining your own gateway. Start free, no card.