What's New

Updated on 2026/07/10 GMT+08:00

The tables below describe the functions released in each Cloud Firewall version and corresponding documentation updates. New features will be successively launched in each region.

June 2026

No.

Feature

Description

Phase

Document

1

Optimization of critical operation confirmations

When you disable a protection rule, delete a protection rule, disable basic protection, or disable virtual patches on the management console, the system displays a risk warning and a confirmation pop-up window to prevent service disruption due to accidental misconfiguration.

Commercial use

Managing Protection Rules

Configuring Basic IPS Protection

Configuring Virtual Patching

January 2026

No.

Feature

Description

Phase

Document

1

Resource statistics

  • Key usage metrics, including the number of protected VPCs, the total number of VPCs that can be protected, and the VPC border protection bandwidth, have been added to the VPC border firewall management page.

  • Key statistics parameters, including the number of protection rules, number of inbound rules, and number of outbound rules, have been added to the protection rule page.

Commercial use

Viewing VPC Border Firewall Information

Viewing Protection Rules

2

Batch export for inactive policies

To simplify rule filtering and routine O&M, you can now export details on inactive policies from the policy assistant.

Commercial use

Policy Assistant

3

Batch export for traffic analysis data

You can now batch-export the following traffic analysis data from the management console as a list:

  • Inbound traffic: EIP analysis and access source IP address analysis

  • Outbound traffic: external IP addresses, external domain names, public network assets initiating outbound connections, and private network assets initiating outbound connections

  • Inter-VPC access traffic: private IP address activity details

Commercial use

Inbound Traffic

Outbound Traffic

Inter-VPC Access Traffic

4

Critical operation protection

The console now supports sensitive operation protection. When this feature is enabled, the system enforces identity authentication during critical actions, such as protection policy deletion, to prevent unauthorized configuration changes.

Commercial use

Critical Operation Protection

5

Confirmation for virtual patch updates

When you update a virtual patch on the management console, a confirmation dialog box is displayed to prevent accidental misconfigurations from disrupting services.

Commercial use

Configuring Virtual Patching

6

Optimized status indicators for inactive policies

On the protection rule page, if a rule has not been matched for a month, the system displays the Inactive status next to the rule name. You can hover over this status to view the rule's match count and its last match time.

Commercial use

Viewing Protection Rules

December 2025

No.

Feature

Description

Phase

Document

1

Optimized policy assistant

The visual layout of the policy assistant has been optimized. The details of inactive policies are now displayed on a dedicated page for easier viewing.

Commercial use

Viewing Protection Information Using the Policy Assistant

2

Optimized traffic analysis

The visual layout of the traffic analysis feature has been optimized, moving relevant metrics to dedicated pages:

  • Inbound traffic: The EIPs and source IP addresses are now displayed on dedicated pages.

  • Outbound traffic: The external IP addresses, external domain names, public network assets initiating outbound connections, and private network assets initiating outbound connections are displayed on dedicated pages.

  • Inter-VPC traffic: Private IP address activity details are now displayed on a dedicated page.

Commercial use

Viewing Inbound Traffic

Viewing Outbound Traffic

Viewing Inter-VPC Access Traffic

June 2025

No.

Feature

Description

Phase

Document

1

Optimized protection rule management

When you add a protection rule, you can configure one or more types in the same rule. The following types can be configured at the same time:
  • IP address and IP address group

  • IP address, IP address group, and network domain name

  • IP address, IP address group, and network domain name group

  • Application domain name and application domain name group

  • Service and service group

Commercial use

Configuring Internet Border Protection Rules

Configuring VPC Border Protection Rules

Configuring NAT Gateway Border Protection Rules

May 2025

No.

Feature

Description

Phase

Document

1

Traffic blocking

CFW can quickly block attacks from a large number of malicious IP addresses.

Commercial use

Traffic Blocking

2

One-click kill switch and one-click restoration

CFW supports the one-click kill switch and one-click restoration functions. You can quickly disable or enable the EIP protection provided by the current firewall.

Commercial use

One-click Kill Switch and One-click Restoration

July 2024

No.

Feature

Description

Phase

Document

1

VPC border protection based on domain names

Added domain name access control in VPC border protection.

Commercial use

VPC Border Protection Rules

2

DNAT protection

CFW can protect DNAT traffic.

Commercial use

Adding a Protection Rule

3

Schedule

You can configure schedules to make protection rules take effect only within the specified time range.

Commercial use

Schedule

March 2024

No.

Feature

Description

Phase

Document

1

Security reports

CFW can generate daily, weekly, or user-defined security reports based on the log report template you created, and send the reports in the specified mode within the specified period.

Commercial use

Security Reports

2

Alarm notification for abnormal external connections

CFW allows you to set alarm notifications for abnormal external connections. If an abnormal IP address or domain name is detected, an alarm notification is sent.

Commercial use

Alarm Notification

December 2023

No.

Feature

Description

Phase

Document

1

Pre-defined address groups

CFW provides you with predefined address groups, including NAT64 Address Set and WAF_Back-to-Source_IP_Addresses, to help you quickly obtain the back-to-source IP addresses to be allowed.

Commercial use

Managing IP Address Groups

2

Pre-defined service groups

CFW provides predefined service groups, including Web Service, Database, and Remote Login and Ping, to help you quickly configure protection policies in different scenarios.

Commercial use

Managing Service Groups

November 2023

No.

Feature

Description

Phase

Document

1

Auto protection on new EIPs

After auto protection on new EIPs is enabled, protection will be automatically enabled for new EIPs, and the EIP traffic will pass through and be protected by the firewall.

Commercial use

Viewing EIP Information

2

Security Dashboard

You can use the policy assistant to quickly check protection rule hits and adjust rules in a timely manner.

Commercial use

Policy Assistant

3

Notification of unprotected EIPs

You can get notified of unprotected EIPs after you enable this alarm notification item.

Commercial use

Alarm Notification

4

Optimized traffic analysis page

Added visualized information about top N inbound, outbound, and inter-VPC traffic statistics on the traffic analysis page.

Commercial use

Traffic Analysis

5

Optimized Dashboard page

Optimized the display of traffic statistics and added traffic trends on the Dashboard page.

Commercial use

CFW Console Dashboard

6

Security dashboard

The security dashboard displays the high-frequency attacks blocked by IPS. You can check the IPS defense status and adjust IPS defense actions in a timely manner.

Commercial use

Security Dashboard

July 2023

No.

Feature

Description

Phase

Document

1

Antivirus

The anti-virus function identifies and processes virus files through virus feature detection to prevent data damage, permission change, and system breakdown caused by virus files.

Commercial use

Managing the Antivirus Function

May 2023

No.

Feature

Description

Phase

Document

1

Inter-VPC border protection policy import and export

You can import and export inter-VPC border firewall access control policies.

Commercial use

Managing Protection Rules in Batches

2

Sensitive directory scan defense

Defend against scan attacks on sensitive directories in real time.

Commercial use

Configuring Intrusion Prevention

3

Reverse shell defense

Defend against reverse shells.

Commercial use

Configuring Intrusion Prevention

4

Custom IPS signature

You can configure network detection signature rules in CFW. CFW will detect threats in data traffic based on signatures.

Commercial use

Custom IPS Signature

April 2023

No.

Feature

Description

Phase

Document

1

Network packet capture

You can use the packet capture function to locate network faults and attacks.

Commercial use

Network Packet Capture

2

Domain group protection

A domain name group is a collection of multiple domain names or wildcard domain names.

You can configure domain name groups to protect domains in batches.

Commercial use

Managing Domain Groups

March 2023

No.

Feature

Description

Phase

Document

1

User-defined basic defense

You can check the CVE ID, risk level, and attack type of a basic IPS defense rule and modify defense actions.

Commercial use

Basic Defense Rule Management

2

CFW professional edition

Internet border protection, Internet ACL, full network traffic analysis, network intrusion prevention system (IPS), inter-VPC traffic protection, and inter-VPC asset protection

Commercial use

Editions

3

Alarm notification

CFW interconnects with Simple Message Notification (SMN) to send IPS attack logs and excessive traffic warning through the notification method (email or SMS) you set.

Commercial use

Alarm Notification

November 2022

No.

Feature

Description

Phase

Document

1

API calling

APIs can be invoked through the API Explorer.

Commercial use

API Overview

August 2022

No.

Feature

Description

Phase

Document

1

CFW OBT test

Launched the first open beta test (OBT).

--

What Is CFW?