Help Center/ Cloud Firewall/ User Guide/ Managing VPC Border Firewalls/ VPC Mode/ Step 1: Create a Firewall (VPC Mode)
Updated on 2024-01-12 GMT+08:00

Step 1: Create a Firewall (VPC Mode)

A VPC border firewall can collect statistics on the traffic between VPCs, helping you detect abnormal traffic. This section describes how to create a VPC border firewall.

Constraints

Only the professional edition supports VPC border firewalls.

Procedure

  1. Log in to the management console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. In the navigation pane, click and choose Security & Compliance > Cloud Firewall. The Dashboard page will be displayed, as shown in Figure 1.

    Figure 1 CFW Dashboard

  4. (Optional) If the current account has only one firewall instance, the firewall details page is displayed. If there are multiple firewall instances, click View in the Operation column to go to the details page.
  5. In the navigation pane, choose Assets > Inter-VPC Border Firewalls.
  6. Click Create Firewall.
  7. Configure a CIDR block. An inspection VPC will be automatically created by default.

    Figure 2 Network planning

    Pay attention to the following restrictions during network planning:

    • After a firewall is created, its CIDR block cannot be modified.
    • This CIDR block cannot overlap with the private CIDR block to be protected, or routing conflicts and protection failures may occur.
    • The CIDR block 10.6.0.0/16-10.7.0.0/16 is reserved for CFW and cannot be specified.

  8. Click OK.

Related Operations

Unsubscription: To unsubscribe from a VPC border firewall, you must unsubscribe from the CFW instance associated with it.