---
title: "Container Firewall"
source: "https://www.tigera.io/tigera-products/container-firewall/"
description: "Protect containers with Calico's container firewall. Apply zero-trust, workload-level controls to Kubernetes traffic and integrate with existing firewalls."
---

Solution

# Container Firewall

Secure containerized workloads with network security controls for hybrid and multi cloud Kubernetes environments.

[Start Free](https://www.calicocloud.io/)
[Get a Demo](https://www.tigera.io/demo/)

![Zero-Trust Explainer Video](https://embed-ssl.wistia.com/deliveries/18044197b127b6a20e6c89af028a8136c78c0485.jpg?image_crop_resized=612x344)

## Benefits

Improves the network security posture of containerized workloads across multi-cluster, multi-and hybrid cloud environments

![This is a firewall icon.](https://www.tigera.io/app/uploads/2023/09/icon-WAF.svg)

### Protect Outbound Traffic

Secure workload access to external resources with advanced network policies and egress gateways

![Networking icon.](https://www.tigera.io/app/uploads/2023/09/icon-clustermesh.svg)

### Prevent Lateral Movement of Threats

Enforce Zero-trust policies to restrict east-west traffic between untrusted pods

![Threat protection icon.](https://www.tigera.io/app/uploads/2023/09/icon-IDS-IPS.svg)

### Detect and Block Attacks

Prevent network-based attacks from malicious sources at the granular workload-level

## Trusted by Customers Worldwide

[![Orange logo](https://www.tigera.io/app/uploads/2022/03/logo-Orange.png)](http://www.orange.com/en)

[![Essentra logo](https://www.tigera.io/app/uploads/2022/04/logo-Essentra.png)](https://www.essentra.com/en)

[![Siemens Healthineers logo](https://www.tigera.io/app/uploads/2022/09/logo-siemens-healthineers.png)](https://www.siemens-healthineers.com/)

[![RBC logo](https://www.tigera.io/app/uploads/2024/05/logo-RBC.png)](https://www.rbcroyalbank.com/)

[![Marsh McLennan logo](https://www.tigera.io/app/uploads/2022/03/logo-Marsh-and-McLennan.png)](http://www.mmc.com/)

[![Presidio logo](https://www.tigera.io/app/uploads/2024/05/logo-Presidio.png)](https://www.presidio.com/)

[![Box logo](https://www.tigera.io/app/uploads/2022/03/logo-box.png)](http://www.box.com/home)

[![Nvidia logo](https://www.tigera.io/app/uploads/2024/05/logo-Nvidia.png)](https://www.nvidia.com/)

[![FM Global logo](https://www.tigera.io/app/uploads/2023/03/logo-FM-Global.png)](https://www.fmglobal.com/)

[![Upwork logo](https://www.tigera.io/app/uploads/2022/12/logo-upwork.png)](https://www.upwork.com/)

[![GoDaddy logo](https://www.tigera.io/app/uploads/2023/03/logo-GoDaddy.png)](https://www.godaddy.com/)

[![Arvato Systems logo](https://www.tigera.io/app/uploads/2025/01/logo-Arvato-systems.png)](https://www.arvato-systems.com/)

[![Aldagi logo](https://www.tigera.io/app/uploads/2022/10/logo-aldagi.png)](https://aldagi.ge/en/)

[![NBC Universal logo](https://www.tigera.io/app/uploads/2022/09/logo-NBC-Universal.png)](https://www.nbcuniversal.com/)

[![Chipotle logo](https://www.tigera.io/app/uploads/2024/05/logo-Chipotle.png)](https://www.chipotle.com/)

[![Meridianlink logo](https://www.tigera.io/app/uploads/2022/03/logo-Meridianlink.png)](http://www.meridianlink.com/)

[![Mulligan Funding logo](https://www.tigera.io/app/uploads/2022/03/logo-MulliganFunding.png)](https://www.mulliganfunding.com/)

[![HanseMerkur logo](https://www.tigera.io/app/uploads/2022/03/logo-HanseMerkur.png)](http://www.hmrv.de/en)

[![Fiserv logo](https://www.tigera.io/app/uploads/2022/12/logo-fiserv.png)](https://www.fiserv.com/)

[![Berenberg logo](https://www.tigera.io/app/uploads/2022/03/logo-BERENBERG.png)](http://www.berenberg.de/en/)

[![eHealth logo](https://www.tigera.io/app/uploads/2023/10/logo-eHealth.png)](https://www.tigera.io/ehealth-case-study/)

[![Coinmetrics logo](https://www.tigera.io/app/uploads/2022/03/logo-coinmetrics.png)](http://coinmetrics.io/)

## Solution Architecture

![Solution Architecture - Calico container firewall with IDS/IPS, anomaly detection, honeypods, DPI, workload-centric WAF diagram](https://www.tigera.io/app/uploads/2023/10/Solution-Architecture-Container-Firewall-1.svg)

![Kubernetes pods show allowed and blocked communication with external services.](https://www.tigera.io/app/uploads/2022/03/Blog-Zero-Trust-for-Cloud-Native-workloads-Part1.png)

### Secure Outbound Traffic

Deploy granular, zero-trust workload access controls from individual pods in Kubernetes clusters to external resources, including databases, internal applications, 3rd-party cloud APIs, and SaaS applications.

Secure pods using fine-grained DNS egress policies and NetworkSets.

[Learn More](https://www.tigera.io/features/access-controls/)

![Universal Firewall Integration diagram](https://www.tigera.io/app/uploads/2021/09/Universal-Firewall-Integration-diagram02.png)

### Egress Gateway

Identify the traffic source from a Kubernetes cluster at the namespace or pod level to enforce traffic policies using existing network security tools such as perimeter firewalls.

Assign a fixed, routable IP to a Kubernetes namespace to identify workloads running within that namespace.

![Service Graph Screenshot](https://www.tigera.io/app/uploads/2023/04/service-graph-14.png)

### Network Visibility

Get complete network topology and traffic visibility with a graph-based visualization of your Kubernetes deployments. Troubleshoot security and compliance gaps, connectivity breakdowns, anomalous behavior, and security policy violations.

![Solution architecture elements: cloud, security shield, checklist, and magnifying glass](https://www.tigera.io/app/uploads/2022/09/Workload-based-ids-ips.png)

### Intrusion Detection and Prevention

Protect against data exfiltration and malware attacks by blocking communication to known malicious IPs, domains, and VPNs by ingesting global threat intelligence feeds.

Stop zero-day attacks with heuristics-based learning of anomalous network activity. Apply deep-packet inspection (DPI) to selective workloads to detect suspicious activity.

Detect and prevent OWASP Top 10 attacks with workload-centric web application firewall (WAF). Intercept DDoS attacks by blocking requests from malicious IPs.

[Learn More](https://www.tigera.io/tigera-products/service-mesh/)

![Service Graph displaying connected services and HTTP flow data.](https://www.tigera.io/app/uploads/2022/09/service-graph-06.png)

### Application-Layer Policy

Apply security controls at the application level to secure pod-to-pod traffic, including HTTP methods and URL paths. Eliminate the operational complexity of deploying an additional service mesh.

Gain application-layer visibility into service-to-service communication.

![Edit Policy Segmentation Granularity Screenshot](https://www.tigera.io/app/uploads/2022/09/Edit-Policy-Segmentation-Granularity.png)

### Dynamic Microsegmentation

Achieve workload isolation based on environments, application tiers, compliance needs, user access, and individual workload requirements. Get automatic and continuous policy recommendations for namespace-based isolation.

Enforce consistent segmentation policies across the environment.

[Learn More](https://www.tigera.io/features/microsegmentation/)

![Policies Board Screenshot](https://www.tigera.io/app/uploads/2023/01/Policies-Board-05.png)

### Security Policy Management

Collaboratively author, stage, preview, enforce, and manage security policies with Calico’s unified policy framework. Test policy before deployment using staged policies. Deploy policies in hierarchical policy tiers based on roles and permissions to ensure consistent enforcement of policies. The manager UI has a policy board so teams can easily view and manage all active and inactive security policies in the Kubernetes cluster.

## Available on Microsoft Azure, AWS, and Google Marketplace

Get started right away on Azure, AWS, or Google Cloud—every Calico component you need to get up and running is ready to go.

[On Azure](https://azuremarketplace.microsoft.com/en-ca/marketplace/apps/tigerainc1620235671643.calicocloudsaas?tab=overview)
[On AWS](https://aws.amazon.com/marketplace/pp/prodview-pq3tgvtlj3wce)
[On Google Cloud](https://console.cloud.google.com/marketplace/product/tigera-public/calico-cloud?inv=1&invt=Ab27_g&project=tigera-public)

![Microsoft Azure, AWS, and Google Cloud logos.](https://www.tigera.io/app/uploads/2025/07/Solution-cloud-marketplace-AWS-Azure-03.svg)

## Customer Testimonial

Here’s what our customers are saying about us

![Quotation marks](https://www.tigera.io/app/themes/tigera2021/dist/img/quotes-sign.svg)

After implementing Calico WAF as a sidecar, NuraLogix went from an average latency of 30 milliseconds down to 1 millisecond. Overall, NuraLogix’s software works better, is faster, and is more scalable thanks to Calico Cloud.

Romil Khanna

Data Security Officer & Platform Engineering Team Lead,
NuraLogix

![Nuralogix Logo](https://www.tigera.io/app/uploads/2024/03/logo-NuraLogix-170x60-1.png)

[Learn More](https://www.tigera.io/nuralogix-case-study/)

[Read Customer Stories](https://www.tigera.io/customer-stories/)

## Featured Resources

Developer-created resources to help you secure your Kubernetes deployment

![Transforming container network security with Calico Container Firewall](https://www.tigera.io/app/uploads/2023/09/Transforming-Container-Network-Security-with-Calico-Container-Firewall.png)

Blog

### Transforming container network security with Calico Container Firewall

Network security for containers and Kubernetes needs a new approach for hybrid, multi-cloud environments.

[Read More](https://www.tigera.io/blog/transforming-container-network-security-with-calico-container-firewall/)

![Microsegmentation Datasheet](https://www.tigera.io/app/uploads/2023/04/Featured-resources-Microsegmentation.png)

Datasheet

### Microsegmentation Datasheet

Scalable, unified microsegmentation for cloud-native workloads across all of your environments.

[Read More](https://info.tigera.io/rs/805-GFH-732/images/datasheet-microsegmentation.pdf)

![Evaluating container firewalls for Kubernetes network security](https://www.tigera.io/app/uploads/2023/09/Evaluating-container-firewalls-for-Kubernetes-network-security.png)

Blog

### Evaluating container firewalls for Kubernetes network security

Can NGFW container firewalls protect cloud-native applications?

[Read More](https://www.tigera.io/blog/deep-dive/evaluating-container-firewalls-for-kubernetes-network-security/)

[All Resources](https://www.tigera.io/resources/)

![Calico Logo](https://www.tigera.io/app/uploads/2026/01/Calico-logo-2026-black-text.svg)

## Ready to Get Started?

Get started for free or request a demo to see Calico in action

<!-- plugin=object-cache-pro client=phpredis metric#hits=9310 metric#misses=33 metric#hit-ratio=99.7 metric#bytes=2584799 metric#prefetches=0 metric#store-reads=535 metric#store-writes=56 metric#store-hits=560 metric#store-misses=22 metric#sql-queries=36 metric#ms-total=2670.64 metric#ms-cache=436.09 metric#ms-cache-avg=0.7391 metric#ms-cache-ratio=16.3 sample#redis-hits=14944210 sample#redis-misses=5615577 sample#redis-hit-ratio=72.7 sample#redis-ops-per-sec=459 sample#redis-evicted-keys=0 sample#redis-used-memory=100297400 sample#redis-used-memory-rss=90492928 sample#redis-memory-fragmentation-ratio=0.9 sample#redis-connected-clients=3 sample#redis-tracking-clients=0 sample#redis-rejected-connections=0 sample#redis-keys=49532 -->
