Help Center/ Cloud Firewall/ FAQs/ Troubleshooting/ Why Does a Protection Rule Not Take Effect?
Updated on 2026-07-14 GMT+08:00

Why Does a Protection Rule Not Take Effect?

All Traffic Is Allowed Even If a Rule Is Configured to Allow Only Several EIPs

After EIP protection is enabled on CFW, the access control policy allows all traffic by default. If you want to allow traffic of only several EIPs, you need to configure a protection rule to block all traffic and set the lowest priority.

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  4. In the navigation pane, choose Internet Border Protection Rules or VPC Border Protection Rules under Access Control.
  1. Configure a global blocking rule.

    Click Add Rule. Use the parameter settings shown below and configure other parameters as needed.
    Table 1 Blocking all traffic

    Parameter

    Example Value

    Description

    Direction

    Inbound

    Direction of the protected traffic.

    Source

    Any

    Origin of network traffic.

    Destination

    Any

    Receiver of network traffic.

    Service

    Any

    Protocol, source port, and destination port of network traffic.

    Application

    Any

    Protection policy for application layer protocols.

    Action

    Block

    Action taken when traffic passes through the firewall.

    You are advised to enable the rules after adding all required ones.

  2. Configure an allow rule.

    For details about how to add a protection rule, see Configuring Protection Rules to Block or Allow Internet Border Traffic.

  3. Set Priority of the global blocking rule in 5 to the lowest.

    For details, see Adjusting the Priority of a Protection Rule.

  4. Enable all rules.

    You are advised to enable the allow rules prior to the blocking rules.

Blocked IP Addresses Are Still Allowed Through Even If a Global Blocking Rule Is Configured

The EIP protection rules configured on CFW are applied based on the EIP management list. If you have enabled global blocking (0.0.0.0/0) but the traffic of EIPs not in an allow rule is allowed through, check whether the EIPs are protected. For more information, see Enabling EIP Protection.