Configuring Protection Rules to Block or Allow NAT Gateway Border Traffic
Scenario
After protection is enabled with no access control policy configured, CFW allows all traffic by default. You can configure protection rules to allow or block traffic forwarded by NAT gateways between the Internet and private network assets. Refined control by private IP address, port, and domain name is supported to meet private network egress security, access control, and compliance audit requirements.
This section describes how to configure protection rules for a NAT gateway firewall.
Protection Rule Description
The protected objects, actions, and application scenarios of protection rules are as follows.
| Name | Description |
|---|---|
| Protected object |
|
| Network type |
|
| Action |
|
| Scenario | You can configure protection rules in the following scenarios:
CAUTION: If your IP address is a back-to-source WAF IP address, you are advised to configure a protection rule or the whitelist to allow its access. Exercise caution when configuring a protection rule to block access, which may affect your services.
|
Specification Limitations
Only the professional edition supports NAT traffic (private IP address) protection.
Constraints
| Type | Description |
|---|---|
| Quota limit |
|
| Restrictions on domain name protection |
|
| Restrictions on regions | A protection rule with its source or destination set to a region (geographical location) takes effect only for IPv4 protected objects. |
| Restrictions on the use of predefined address groups | Pre-defined Address Groups can be configured only for Source address for a DNAT rule. |
| Other restrictions |
|
Impacts on Services
When configuring a blocking rule, if address translation or proxy is involved, evaluate the impact of blocking IP addresses with caution.
Adding a NAT Gateway Traffic Protection Rule
The procedures for adding a protection rule in scenarios are as follows.
- Enable NAT traffic protection. For details, see Enabling NAT Gateway Traffic Protection.
- (Optional) To add multiple IP addresses and services (protocols, source ports, and destination ports), add their groups first.
- For details about how to add multiple IP addresses, see Managing IP Address Groups.
- For details about how to add multiple services, see Managing Service Groups.
- In the navigation pane of the CFW console, choose . The Internet Border Protection Rules page is displayed.
- Add a protection rule.
On the Protection Rules tab, click NAT. Click Add Rule and configure parameters. For details, see Table 1.
Table 1 DNAT protection rule parameters Parameter
Description
Name
Name of a custom protection rule.
Direction
Select DNAT.
Source
Set the party that initiates a session.- IP Address/IP address group/Countries and regions:
- IP Address: Enter EIPs. This parameter can be configured in the following formats:
- A single EIP, for example, xx.xx.10.5
- Consecutive EIPs, for example, xx.xx.0.2-xx.xx.0.10
- EIP segment, for example, xx.xx.2.0/24
- IP address group. You can configure multiple EIPs.
If Direction is set to Inbound, a predefined address group can be configured for the source address.
For details about user-defined and predefined IP address groups, see Managing IP Address Groups.
- Countries and regions: A continent, a country, or a region
- IP Address: Enter EIPs. This parameter can be configured in the following formats:
- Any: any source address
Destination
Set the recipient of a session.- IP Address/IP address group:
- IP address: Enter private IP addresses. You can set a single IP address, consecutive IP addresses, or an IP address segment.
- A single IP address, for example, 192.168.10.5
- Consecutive IP addresses, for example, 192.168.0.2-192.168.0.10
- Address segment, for example, 192.168.2.0/24
- IP address group. You can configure multiple private IP addresses.
For details about how to add an IP address group, see Adding a User-defined IP Address Group.
- IP address: Enter private IP addresses. You can set a single IP address, consecutive IP addresses, or an IP address segment.
- Any: any destination address
Service
- Service/Service group:
- Service: Set Protocol, Source Port, and Destination Port.
- Protocol: The value can be TCP, UDP, or ICMP.
- Source/Destination Port: If Protocol is set to TCP or UDP, you need to set the port number.
To specify all the ports of an IP address, set Port to 1-65535.
You can specify a single port. For example, to manage access on port 22, set Port to 22.
To set a port range, use a hyphen (-) between the starting and ending ports. For example, to manage access on ports 80 to 443, set Port to 80-443.
- Service group: A collection of services (protocols, source ports, and destination ports).
For details about how to add a custom service group, see Adding a Service Group. For details about predefined service groups, see Viewing a Predefined Service Group.
- Service: Set Protocol, Source Port, and Destination Port.
- Any: any protocol type or port number
Application
(Optional) Configure protection policies for application-layer protocols.- When Service is set to Any, all application types are supported.
- If Service is set to Service and Protocol is set to TCP, TCP applications, such as HTTP and HTTPS, are supported.
- If Service is set to Service and Protocol is set to UDP, UDP applications, such as DNS and RDP, are supported.
Select an application-layer protocol based on the value of Protocol under Service. If no protocol is selected, this parameter is set to Any by default.
Protection Action
Set the action to be taken when traffic passes through the firewall.- Allow: Traffic is forwarded.
- Block: Traffic is not forwarded.
Status
Whether a protection rule is applied immediately.
: The policy takes effect immediately after being configured.
: The policy is disabled.
Priority
Set the priority of the rule. If multiple security policies are configured, the security policies will be matched based on their priorities. Once traffic matches a security policy, it will not be checked against others. Assign priorities carefully. Specific policies should take precedence over general ones.- Pin on top: indicates that the priority of the policy is set to the highest.
- Lower than the selected rule: indicates that the policy priority is lower than a specified rule.
Schedule Management
(Optional) Click Schedule Management and configure when the rule is in effect. Select or add a schedule.
Allow Long Connection
If only one service is configured in the current protection rule and Protocol is set to TCP or UDP, you can configure the service session aging time (unit: second).
Long Connection Duration
If Allow Long Connection is set to Yes, you need to set the persistent connection duration and set hour, minute, and second.
Tag
(Optional) Tags are used to identify rules. You can use tags to classify and search for protection rules.
Description
(Optional) Usage and application scenario
- IP Address/IP address group/Countries and regions:
- Click OK to complete the protection rule configuration.
If the source addresses of the protection rule contain a WAF back-to-source IP address, enter CONFIRM in the displayed dialog box and click OK.
After a protection rule is configured and enabled, it takes effect immediately.
- Enable NAT traffic protection. For details, see Enabling NAT Gateway Traffic Protection.
- (Optional) To add multiple IP addresses and services (protocols, source ports, and destination ports), add their groups first.
- For details about how to add multiple IP addresses, see Managing IP Address Groups.
- For details about how to add multiple services, see Managing Service Groups.
- In the navigation pane of the CFW console, choose . The Internet Border Protection Rules page is displayed.
- Add a protection rule.
On the Protection Rules tab, click NAT. Click Add Rule and configure parameters. For details, see Table 2.
Table 2 SNAT protection rule parameters Parameter
Description
Rule Type
Select NAT to protect the traffic of the NAT gateway. Private IP addresses can be configured.
NOTE:To select the NAT rule, ensure that:- The professional edition firewall is used. For details about how to upgrade your edition, see Upgrading a CFW.
- The VPC border firewalls have been configured. For details, see Managing VPC Border Firewalls
Name
Name of a custom protection rule.
Direction
Select SNAT.
Source
Set the party that initiates a session.- IP Address/IP address group:
- IP Address: Enter private IP addresses. You can set a single IP address, consecutive IP addresses, or an IP address segment.
- A single IP address, for example, 192.168.10.5
- Consecutive IP addresses, for example, 192.168.0.2-192.168.0.10
- Address segment, for example, 192.168.2.0/24
- IP address group: You can add multiple private IP addresses to an IP address group. For details about how to add an IP address group, see Adding an IP Address Group.
- IP Address: Enter private IP addresses. You can set a single IP address, consecutive IP addresses, or an IP address segment.
- Any: any source address
Destination
Set the recipient of a session.- IP Address/IP address group/Countries and regions/Domain name/Domain name group:
- IP Address: Enter EIPs. This parameter can be configured in the following formats:
- A single EIP, for example, xx.xx.10.5
- Consecutive EIPs, for example, xx.xx.0.2-xx.xx.0.10
- EIP segment, for example, xx.xx.2.0/24
- IP address group. You can configure multiple EIPs.
If Direction is set to Inbound, a predefined address group can be configured for the source address.
For details about user-defined and predefined IP address groups, see Managing IP Address Groups.
- Countries and regions: A continent, a country, or a region
- Domain Name/Domain Name Group:
- Application: One or multiple domain names or wildcard domain names can be protected. The setting applies to application-layer protocols, including HTTP, HTTPS, TLS, SMTPS, and POPs. Domain names are used for matching.
- Network: Supports protection for one or multiple domain names. Applies to network-layer protocols and supports all protocols. The resolved IP addresses are used for matching.
NOTE:- To protect the domain names of HTTP, HTTPS, TLS, SMTPS, and POPS applications, you can select any options.
- To protect the wildcard domain names of HTTP, HTTPS, TLS, SMTPS, or POPS, you select any option under Application. (A wildcard domain name is in the format of *.Domain_name. The wildcard character * matches any character or string. For example, *.example.com.)
- To protect a single domain name of other application types (such as FTP, MySQL, and SMTP), select Network and select any option from the drop-down list. (If Domain name is selected, up to 600 IP addresses can be resolved.)
- If you need to configure the wildcard domain names or application domain name groups of the HTTP, HTTPS, TLS, SMTPS, and POPS applications, and the network domain groups of other application types for the same domain name, ensure that the priority of the Network protection rule is higher than that of the Application protection rule.
- For details about application- and network-type domain names, see Adding a Domain Name Group.
- IP Address: Enter EIPs. This parameter can be configured in the following formats:
- Any: any destination address
Service
- Service/Service group:
- Service: Set Protocol, Source Port, and Destination Port.
- Protocol: The value can be TCP, UDP, or ICMP.
- Source/Destination Port: If Protocol is set to TCP or UDP, you need to set the port number.
To specify all the ports of an IP address, set Port to 1-65535.
You can specify a single port. For example, to manage access on port 22, set Port to 22.
To set a port range, use a hyphen (-) between the starting and ending ports. For example, to manage access on ports 80 to 443, set Port to 80-443.
- Service group: A collection of services (protocols, source ports, and destination ports).
For details about how to add a custom service group, see Adding a Service Group. For details about predefined service groups, see Viewing a Predefined Service Group.
- Service: Set Protocol, Source Port, and Destination Port.
- Any: any protocol type or port number
Application
(Optional) Configure protection policies for application-layer protocols.- When Service is set to Any, all application types are supported.
- If Service is set to Service and Protocol is set to TCP, TCP applications, such as HTTP and HTTPS, are supported.
- If Service is set to Service and Protocol is set to UDP, UDP applications, such as DNS and RDP, are supported.
Select an application-layer protocol based on the value of Protocol under Service. If no protocol is selected, this parameter is set to Any by default.
Protection Action
Set the action to be taken when traffic passes through the firewall.- Allow: Traffic is forwarded.
- Block: Traffic is not forwarded.
Status
Whether a protection rule is applied immediately.
: The policy takes effect immediately after being configured.
: The policy is disabled.
Priority
Set the priority of the rule. If multiple security policies are configured, the security policies will be matched based on their priorities. Once traffic matches a security policy, it will not be checked against others. Assign priorities carefully. Specific policies should take precedence over general ones.- Pin on top: indicates that the priority of the policy is set to the highest.
- Lower than the selected rule: indicates that the policy priority is lower than a specified rule.
Schedule Management
(Optional) Click Schedule Management and configure when the rule is in effect. Select or add a schedule.
Allow Long Connection
If only one service is configured in the current protection rule and Protocol is set to TCP or UDP, you can configure the service session aging time (unit: second).
Long Connection Duration
If Allow Long Connection is set to Yes, you need to set the persistent connection duration and set hour, minute, and second.
Tag
(Optional) Tags are used to identify rules. You can use tags to classify and search for protection rules.
Description
(Optional) Usage and application scenario
- Click OK to complete the protection rule configuration.
Viewing Protection Rule Hits
After your services run for a period of time, you can view the number of rule hits in the Hits column of the protection rule list.
You can click a number in the Hits column to go to the Access Control Logs tab page and view log details. For details, see Log Query.
Follow-up Operations
- Policy hits: For details about the protection overview, see Viewing Protection Information Using the Policy Assistant. For details about logs, see Viewing Attack Event Logs.
- For details about the traffic trend and statistics, see Traffic Center. For details about traffic records, see Log Query.
Related Operations/Documents
After adding a protection rule, you can edit, delete, and adjust the priority of the rule in the rule list.
- For details about how to add protection rules in batches, see Importing and Exporting Protection Policies.
- For details about how to adjust rule priority, see Adjusting the Priority of a Protection Rule.
- For details about how to manage protection rules, such as checking, editing, and deleting rules, see Managing Protection Rules.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot