Help Center> Cloud Firewall> Best Practices> Using CFW to Protect SNAT> Configuring a NAT Protection Rule
Updated on 2024-04-09 GMT+08:00

Configuring a NAT Protection Rule

After verifying the traffic flow, configure protection rules so that the CFW can allow or block traffic accordingly.

Procedure

  1. Log in to the management console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. In the navigation pane on the left, click and choose Security & Compliance > Cloud Firewall. The Dashboard page will be displayed.
  4. (Optional) If the current account has only one firewall instance, the firewall details page is displayed. If there are multiple firewall instances, click View in the Operation column to go to the details page.
  5. In the navigation pane, choose Access Control > Access Policies.
  6. On the Internet Boundaries tab, click Add Rule. In the Add Rule dialog box, configure the following parameters:

    • Protection Rule: NAT protection
    • Source: Select IP address. Enter a private IP address.
    • Destination: Select IP address (and enter a public IP address) or Domain name/Domain name group.
      Figure 1 Configuring a NAT protection rule

  7. Click OK.