← Home  |  PacketUtils

How to Open a Port on Oracle Cloud

If a service runs on your Oracle Cloud instance but the outside world cannot reach it, one of two firewalls is still closed. You need to open both.

The two layers

1. Cloud firewall: the security list (or network security group) attached to your VCN subnet. It is configured in the Oracle Cloud console.
2. Operating system firewall: iptables on Ubuntu images, firewalld on Oracle Linux. It is configured over SSH.

Step 1: Open the port in the console

In the Oracle Cloud console, open your instance and click its subnet under Primary VNIC. Open the subnet's security list (usually Default Security List) and choose Add Ingress Rules. Fill in:

Source CIDR 0.0.0.0/0 (or a single IP such as 203.0.113.5/32 to restrict access)
IP Protocol TCP (or UDP)
Destination Port Range your port, for example 80

If your instance uses a network security group instead, add the same ingress rule to that group.

Step 2: Open the port inside the instance

Ubuntu images (iptables)

Ubuntu images on Oracle Cloud ship with a REJECT rule at the end of the INPUT chain. A rule added after it is never reached, so insert yours at the top (position 1), which always lands above the REJECT rule. Then save so the rule survives a reboot:

Oracle Linux (firewalld)

Step 3: Test it

On the instance, confirm the service is listening on all interfaces, not just localhost:

sudo ss -tlnp

If the address shows 127.0.0.1:PORT, only local connections work. It should show 0.0.0.0:PORT or *:PORT. Then test from another machine with a browser, curl, or nc -vz SERVER_IP PORT.

Still not working?

Rule in the wrong place. Run sudo iptables -L INPUT -n --line-numbers. Your ACCEPT line must appear above the REJECT line. If you also keep DROP rules for specific IPs, place those above your allow rule, because the first matching rule wins.
Wrong subnet. Make sure you edited the security list of the subnet your instance actually uses.
Nothing is listening. Start the service and check with ss -tlnp.
Another firewall. Do not mix ufw and iptables rules on the same instance. Pick one.

FAQ

Why do I need to open the port twice?

Traffic passes the cloud firewall first, then the firewall inside the instance. A port must be allowed by both, so a rule in only one of them does nothing.

Why does Ubuntu on Oracle Cloud need iptables -I instead of -A?

The default INPUT chain ends with a REJECT rule. Appended rules land after it and are never matched, so the new rule has to go above it.

Do I need to reboot after changing the security list?

No. Security list changes apply to new connections shortly after you save them, and iptables rules apply immediately.

Can I open a port for only my own IP?

Yes. Use your address as the source CIDR (for example 203.0.113.5/32) in the security list, and add -s 203.0.113.5 to the iptables command. Our iptables generator builds this for you.