Help Center/ Cloud Firewall/ User Guide/ Cloud Firewall Dashboard
Updated on 2026-09-23 GMT+08:00

Cloud Firewall Dashboard

Scenarios

On the CFW dashboard page, you can view the basic information, overall protection capabilities, traffic topology visualization information, and statistics of your firewall instances. This helps you stay informed about the security status and traffic data of your cloud assets, quickly identify security weaknesses and potential risks, and make informed decisions for future security policy optimization and threat response.

Notes and Constraints

VPC border protection details can be viewed only after a VPC border firewall is configured.

Accessing the Dashboard Page

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region.
  3. On the Dashboard page, you can check the following modules:

    • Switching to or Checking a Firewall Instance: If you have multiple firewall instances under your account, you can switch between them to view the information about each instance.
    • Resource Overview: View the protection status of EIPs and VPCs to identify unprotected assets.
    • Security Events: Check intrusion prevention statistics to quickly identify the cloud assets requiring priority protection.
    • Protection Rules: View the policy matching status to identify redundant policies that have not been matched for a long time.
    • Operations Dashboard: View operation data, such as the peak traffic, 95th percentile bandwidth, traffic trend, and attack trend.
    • Firewall Details: View the edition specifications, protection quota, and bandwidth usage of a firewall instance.

Switching to or Checking a Firewall Instance

Figure 1 Switching to or checking a firewall instance
  • Switch to a firewall instance: Select a firewall from the drop-down list in the upper left corner of the page.

    If you have multiple firewall instances, data for the most recently accessed firewall instance is displayed on the dashboard by default. You can quickly switch to another instance from the drop-down list.

  • Viewing firewall instance information: Click Firewall List in the upper right corner. The firewall list is displayed in the pane on the right.

In the firewall instance list, you can search for or filter instances. After the filtering is successful, you can click the save icon next to the filter box. In the dialog box that is displayed, enter a filter set name and click OK to save the current filter criteria as a quick filter set. This set will be displayed in the drop-down list for quick reuse.

Table 1 Firewall instance information

Parameter

Description

Firewall Name/ID

Name and ID of the firewall.

Status

Firewall status.

Edition

Edition of a firewall.

EIP Protection Available

Maximum number of EIPs that can be protected by the firewall.

Protection Bandwidth

Protection bandwidth of the current firewall.

Billing Mode

Billing mode of the current firewall.

Enterprise Project

Enterprise project that the firewall belongs to.

Resource Overview

In the Resource Overview area on the dashboard, view the protection status of all cloud resources (EIPs and VPCs) in the current region of the current account, including the number of unprotected resources and the total number of resources.

  • You can click the number of a resource to go to the corresponding resource page and view the resource details.

Security Events

In the Security Events area on the dashboard, view the overall protection details of the intrusion prevention function and quickly locate the cloud assets to be protected.

  • In the upper right corner, change the query range, from 5 minutes to 7 days. The custom time interval cannot be less than 5 minutes.
  • Hover your cursor over the number of security events to view the number of events by category. In the displayed tooltip, click View Log to go to the Log Query page and view the log information.
  • View the current protection mode or click Change Protection Mode to go to the Intrusion Prevention page and change the protection mode. For details about how to modify the protection mode, see Adjusting the IPS Protection Mode to Block Network Attacks.
  • Add a protection policy to handle the IP addresses of the abnormal external connections.
    1. Click the number of Abnormal External Destination IP Addresses.
    2. In the displayed dialog box, select an IP address.
    3. Generate an address group:
      • Create as an address group: A new address group will be generated.
      • Add to an existing address group: Add the item to an existing address group.
    4. Add the address group to the protection rule or blacklist/whitelist. For details, see Access Control Policy Overview.

Protection Rules

In the Protection Rules area on the dashboard, view the number of inactive protection rules and the total number of protection rules.

  • Click the number of Policies Inactive for Over a Month to go to the Inactive Policies tab on the Policy Assistant page and view details about the inactive policies.

    You can also choose Access Control > Policy Assistant in the navigation pane on the left of the CFW console. On the displayed page, click the Inactive Policies tab to check the policies that have not been matched for a period of time.

  • Hover your cursor over the number of Total Policies to view the number of policies by category. You can also click View in the tooltip to go to the corresponding protection rule page to view details.

    For example, hover the cursor over the number next to Total Policies and click View next to EIP in the tooltip. The Protection Policies > Access Control > Internet Border Protection Rules > Protection Rules > EIP page is displayed. You can view details about the EIP rules.

Operations Dashboard

In the Operations Dashboard area on the dashboard, view the overall protection statistics of cloud resources in the corresponding scenario.

  • Click the Internet Borders or Inter-VPC Borders tab to view the overall protection statistics of resources.
  • In the upper right corner, change the query range, from 5 minutes to 7 days.
  • Peak Inbound/Outbound Traffic, Inbound/Outbound 95th Percentile Bandwidth, and Blocked Accesses:
    View the traffic blocked by access control policies, the 95th percentile inbound and outbound bandwidth, and the maximum inbound and outbound traffic. For details, see Table 2.
    Table 2 Peak inbound/outbound traffic, inbound/outbound 95th percentile bandwidth, and blocked accesses

    Time Range

    Value

    Last 1 hour

    Maximum value within every minute

    Last 24 hours

    Maximum value within every 5 minutes

    Last 7 days

    Maximum value within every hour

    Custom

    • 5 minutes to 6 hours: maximum value within every minute
    • 6 hours (included) to 3 days: maximum value within every 5 minutes
    • 3 (included) to 7 days (included): maximum value within every 30 minutes
    • Peak traffic: The system collects bandwidth in every statistical period. The maximum value within a certain period of time is regarded as the peak traffic.

      For example, if the outbound peak traffic is 100 Mbit/s, the maximum bandwidth within a certain period of time (for example, 24 hours) is 100 Mbit/s.

    • 95th percentile bandwidth: The system collects bandwidth in every statistical period, and sorts the bandwidth values in descending order, and removes the top 5% bandwidth values. The remaining maximum bandwidth is the 95th percentile bandwidth.

      For example, if the 95th percentile bandwidth in the outbound direction is 100 Mbit/s, that means after the bandwidth values are sorted in descending order and the highest 5% values are removed within a certain period of time (for example, 24 hours), the remaining maximum bandwidth is 100 Mbit/s.

  • Traffic Trend:

    Inbound, outbound, and overall traffic changes. You can view EIPs, Average, or Maximum in the upper right corner. For details about how they are calculated, see Table 3.

    Table 3 Traffic trend statistics

    Time Range

    Average

    Maximum

    Last 1 hour

    Average value within every minute

    Maximum value within every minute

    Last 24 hours

    Average value within every 5 minutes

    Maximum value within every 5 minutes

    Last 7 days

    Average value within every hour

    Maximum value within every hour

    Custom

    • 5 minutes to 6 hours: average value within every minute
    • 6 hours (included) to 3 days: average value within every 5 minutes
    • 3 (included) to 7 days (included): average value within every 30 minutes
    • 5 minutes to 6 hours: maximum value within every minute
    • 6 hours (included) to 3 days: maximum value within every 5 minutes
    • 3 (included) to 7 days (included): maximum value within every 30 minutes

    Note: Data is updated in real time based on traffic statistics.

  • Attacks: View the traffic blocked or allowed by intrusion prevention. For details about how to modify intrusion prevention configurations, see Configuring Basic IPS Protection.
  • Access Control: View the traffic blocked or allowed by access control policies. For details about how to modify access control policies, see Access Control.

Firewall Details

In the Firewall Details area on the dashboard, view details about the current firewall instance.

Table 4 Firewall instance details

Parameter

Description

Related Operations

Basic Information

Edition

Edition of the firewall. Options: Standard, Professional

For details about how to upgrade the edition, see Upgrading a CFW.

Firewall Name

Firewall instance name. You can click to change the name.

-

Firewall ID

Firewall instance ID.

-

Status

Firewall status. It takes about 5 minutes to update the firewall status after purchase or unsubscription.

-

Enterprise Project

Enterprise project that the firewall belongs to.

-

Flavor

Used/Available EIP Protection Quota

Number of protected EIPs/Total number of EIPs under the current CFW instance.

The total number of EIPs that can be protected is as follows:

  • Standard edition: 20 (can be increased to 2,000)
  • Professional edition
    • Yearly/Monthly: 50 (can be increased to 2,000)
    • Pay-per-use: 1,000 (fixed)

For details about how to purchase or unsubscribe from an extended package, see Changing CFW Extended Packages.

Used/Available VPC Protection Quota

Number of protected VPCs/Total number of VPCs under a firewall instance.

Only the professional edition supports VPC border firewalls. The total number of VPCs that can be protected is as follows:

  • Yearly/Monthly: 2 (can be increased to 1,000)
  • Pay-per-use: 20 (fixed)

Internet Border Protection Bandwidth

Maximum inbound or outbound traffic of all EIPs protected by CFW.

The Internet border protection bandwidth is as follows:

  • Standard: up to 10 Mbit/s (can be increased to 50,000 Mbit/s)
  • Professional
    • Yearly/Monthly: up to 50 Mbit/s (can be increased to 50,000 Mbit/s)
    • Pay-per-use: The maximum protection bandwidth is 1 Gbit/s. (It refers to the total traffic passing through the firewall, that is, the Internet border protection bandwidth plus the VPC border protection bandwidth). If you need higher protection bandwidth, submit a service ticket.

VPC Border Protection Bandwidth

Peak east-west traffic that can be protected.

Maximum total traffic of all VPCs protected by CFW.

Only the professional edition supports VPC border firewalls. The VPC border protection bandwidth is as follows:

  • Yearly/Monthly: 200 Mbit/s, which increases with VPC protection quotas.
  • Pay-per-use: The maximum protection bandwidth is 1 Gbit/s. (It refers to the total traffic passing through the firewall, that is, the Internet border protection bandwidth plus the VPC border protection bandwidth). If you need higher protection bandwidth, submit a service ticket.

Used/Available Protection Rules

Number of created protection rules/Total number of protection rules that can be created under a firewall instance.

Transaction Details

Billing Mode

Billing mode of the firewall instance.

For details about the billing modes, see Billing Modes.

Last Transaction Order

Latest transaction order of the firewall instance.

Created

Time at which the firewall instance is created.

Expires

Estimated expiration time of the firewall instance.

Upon Expiration

Billing policy after the firewall instance expires.

Tags

Configure tags to identify firewalls so that you can classify firewall instances.

For details about Tag Management Service (TMS), see Resource Tag Overview.

References