Viewing Inter-VPC Traffic
Scenario
Inter-VPC access traffic analysis visualizes the cross-VPC traffic trends, top IP addresses, ports, and applications, and private network access details to support use cases such as bandwidth analysis, abnormal source tracing, lateral movement risk detection, and graded protection compliance audits and O&M.
This section describes how to view the inter-VPC traffic protected by the current firewall instance.
Specification Limitations
- The data is collected from sessions. The statistics of a session is reported only after it is terminated.
- Traffic data is reported collectively after a session terminates. Consequently, persistent connections may experience a minor data display latency rather than real-time refreshes.
- Supported time ranges span from 5 minutes to 7 days. The system automatically adjusts the data aggregation granularity based on your selection. Custom intervals must be at least 5 minutes.
Viewing the Inter-VPC Access Traffic Dashboard
- Configure and enable VPC border traffic protection, and ensure that existing traffic passes through the VPC.
For details about how to enable VPC border traffic protection, see Enabling VPC Border Traffic Protection.
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane, choose .
- On the Statistics Dashboard page, check the traffic passing through the firewall within a time range, from 5 minutes to 7 days.
- Traffic Dashboard: Information about the maximum traffic between VPCs. Figure 1 Inter-VPC access traffic - traffic dashboard
- Inter-VPC Access: Request and response traffic between VPCs.
The data displayed is the average bits per second (bps) of the sessions ended at the specified time in traffic logs.
Figure 2 Inter-VPC access
Table 1 Value description Time Range
Value
Last 1 hour
Average value within every minute
Last 24 hours
Average value within every 5 minutes
Last 7 days
Average value within every hour
Custom
- 5 minutes to 6 hours: average value within every minute
- 6 hours (included) to 3 days: average value within every 5 minutes
- 3 (included) to 7 days (included): average value within every 30 minutes
- Visualizations: View the top 5 items ranked by specific parameters of inter-VPC traffic within a specified period. For more information, see Table 2. You can click a data record to view the traffic details. A maximum of 50 data records can be viewed. Figure 3 Inter-VPC access traffic - visualized statistics
Table 2 Inter-VPC traffic parameters Parameter
Description
Top Access Source IP Addresses
Source IP addresses of inter-VPC traffic.
Top Destination IP Addresses
Destination IP addresses of inter-VPC traffic.
Top Open Ports
Destination port of inter-VPC traffic.
Application Distribution
Application information about inter-VPC traffic.
- Traffic Dashboard: Information about the maximum traffic between VPCs.
Viewing Private IP Address Accesses
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane on the left, choose . Click the Private IP Address Accesses tab page.
- View the top 50 private IP addresses by traffic within a specified period.
- The table shows the top 50 records with the highest access traffic. Each record includes the top five ports and applications with the highest access traffic.
- To export the private network IP address list, click Export above the list and set the scope of data. The data will be automatically exported to the local PC.
Figure 4 Private IP address accesses
References
- For details about how to check abnormal traffic, see What Can I Do If Services Cannot Be Accessed After a Policy Is Configured on CFW?
- For details about what to do when service traffic exceeds the protection bandwidth, see What Do I Do If My Service Traffic Exceeds the Protection Bandwidth?
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot