Enabling the VPC Border Firewall and Ensuring the Traffic Passes Through CFW
Scenario
Once you create a VPC border firewall and associate it with an enterprise router, the firewall defaults to the Disabled state. In this mode, the firewall engine does not inspect or parse packets, meaning your workloads remain unprotected. You need to manually enable the VPC border firewall to activate policy enforcement. After enabling protection, generate test traffic via cross-VPC service communication. You can then verify the routing state using the CFW traffic logs. This confirms that traffic is successfully routed through, inspected, and filtered by the firewall, validating that your internal network border defenses are active.
This section describes how to enable the VPC border firewall and verify that traffic passes through CFW.
Enabling a VPC Border Firewall
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane, choose Assets > Inter-VPC Border Firewalls.
- Click the
next to Firewall Status and click OK in the displayed dialog box to enable the VPC border firewall.
Verifying That Traffic Passes Through CFW
- Generate traffic. For details, see Verifying Network Connectivity.
- View logs. In the navigation pane, choose . Click the tab and click VPC Border Firewall.
- If a log is generated, CFW is protecting the traffic between VPCs.
- If no logs are recorded, check the configurations of the enterprise router. For details, see Configuring the Enterprise Router to Divert Traffic to CFW.
Follow-up Operations
Once VPC border traffic protection is enabled, your service traffic is routed through CFW. By default, all traffic is allowed. You can monitor traffic trends or configure access control and attack defense policies for the VPC border firewall to achieve fine-grained control over traffic between VPCs and on-premises IDCs, or between separate VPCs.
- View traffic trends and logs.
- View the traffic trends and statistics of CFW. For details, see Traffic Analysis.
- View all traffic logs of CFW. For details, see Traffic Logs.
- Configure protection rules for refined traffic control.
After protection is enabled, all traffic is allowed by default. CFW will block traffic based on the policies you configure.
- Allow or block traffic using protection rules. For details, see Configuring Protection Rules to Block or Allow VPC Border Traffic.
- Allow or block traffic using the blacklist and whitelist. For details, see Adding Blacklist or Whitelist Items to Block or Allow VPC Border Traffic.
- Defend against network attacks: Configure intrusion prevention to handle network attacks. For details, see Configuring Basic IPS Protection.
- Add a protected VPC: For details, see Adding a Protected VPC.
Related Operations
- If you no longer need to protect VPC border traffic, you can disable protection. For details, see Disabling VPC Border Protection.
- For details about adding a protected VPC, see Adding a Protected VPC.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot