Help Center/ Cloud Firewall/ User Guide/ CFW Protection/ Enabling VPC Border Traffic Protection/ Enterprise Router Mode (New)/ Enabling the VPC Border Firewall and Ensuring the Traffic Passes Through CFW
Updated on 2026-07-15 GMT+08:00

Enabling the VPC Border Firewall and Ensuring the Traffic Passes Through CFW

Scenario

Once you create a VPC border firewall and associate it with an enterprise router, the firewall defaults to the Disabled state. In this mode, the firewall engine does not inspect or parse packets, meaning your workloads remain unprotected. You need to manually enable the VPC border firewall to activate policy enforcement. After enabling protection, generate test traffic via cross-VPC service communication. You can then verify the routing state using the CFW traffic logs. This confirms that traffic is successfully routed through, inspected, and filtered by the firewall, validating that your internal network border defenses are active.

This section describes how to enable the VPC border firewall and verify that traffic passes through CFW.

Enabling a VPC Border Firewall

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  4. In the navigation pane, choose Assets > Inter-VPC Border Firewalls.
  5. Click the next to Firewall Status and click OK in the displayed dialog box to enable the VPC border firewall.

Verifying That Traffic Passes Through CFW

  1. Generate traffic. For details, see Verifying Network Connectivity.
  2. View logs. In the navigation pane, choose Log Audit > Log Query. Click the Traffic Logs tab and click VPC Border Firewall.

Follow-up Operations

Once VPC border traffic protection is enabled, your service traffic is routed through CFW. By default, all traffic is allowed. You can monitor traffic trends or configure access control and attack defense policies for the VPC border firewall to achieve fine-grained control over traffic between VPCs and on-premises IDCs, or between separate VPCs.

Related Operations