Help Center> Cloud Firewall> Getting Started> Step 2: Enable EIP Protection
Updated on 2023-12-06 GMT+08:00

Step 2: Enable EIP Protection

When you use CFW for the first time, you need to synchronize assets and enable protection for EIP assets so that your service traffic can pass through CFW.

After EIP protection is enabled, the default action of CFW is Allow. CFW will block traffic based on your protection policy.

Procedure

  1. Log in to the management console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. In the navigation pane, click and choose Security & Compliance > Cloud Firewall. The Dashboard page will be displayed, as shown in Figure 1.

    Figure 1 CFW Dashboard

  4. (Optional) If the current account has only one firewall instance, the firewall details page is displayed. If there are multiple firewall instances, click View in the Operation column to go to the details page.
  5. In the navigation pane, choose Assets > EIPs. The EIP page is displayed. The EIP information is automatically updated to the list. See Figure 2.

    (Optional) Manually refresh the list. Click Synchronize EIP in the upper right corner of the page to import your EIP information to the list and refresh the EIP list.

    Figure 2 EIPs

    Currently, IPv6 addresses cannot be protected.

  1. Enable EIP protection.

    • Enable protection for a single EIP. In the row of the EIP, click Enable Protection in the Operation column.
    • Enable protection for multiple EIPs. Select the EIPs to be protected and click Enable Protection above the table.

  2. On the page that is displayed, check the information and click Bind and Enable. Then the Protection Status changes to Protected.

    After EIP protection is enabled, the default access control policy is Allow.