For servers on the free plan, HeatShield configures a firewall with the following traffic allowed to your server.
To Action From -- ------ ---- 22/tcp SSH ALLOW Anywhere 80/tcp HTTP ALLOW Anywhere 443/tcp HTTPS ALLOW Anywhere
All other traffic to your server is blocked.
By default, HeatShield offers SSH brute force protection by dynamically updating your servers' firewalls to block IP addresses that have attempted malicious SSH login attacks on any of your servers.