Help Center/ Cloud Firewall/ User Guide/ Access Control/ Viewing Protection Information Using the Policy Assistant
Updated on 2026-09-23 GMT+08:00

Viewing Protection Information Using the Policy Assistant

Scenario

In network security management, enterprises usually need to periodically review firewall rules to ensure their effectiveness and efficiency. However, manually reviewing a large number of rules is not only time-consuming but also prone to omissions. After configuring protection policies in CFW, you can view the hit statistics and top blocking events of the protection rules for the past seven days. You can also filter policies that have not been hit over multiple time periods, and then view, edit, or export inactive rules. This helps you optimize your policies and improve firewall rule matching efficiency. The policy assistant of CFW allows you to easily implement automatic review and optimization of firewall rules.

This section describes how to view protection information using the policy assistant.

Viewing Protection Information Using the Policy Assistant

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region.
  3. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  4. In the navigation pane on the left, choose Protection Policies > Access Control > Policy Assistant. The Policy Assistant page is displayed.
  5. On the Statistics Dashboard tab page of the Policy Assistant page, view the statistics of the protection rules under the firewall instance.

    You can select a preset time range directly from the drop-down menu, or specify a custom window to analyze data across any period spanning from 5 minutes to 7 days.

    • Policy Dashboard: Number of accesses that hit policies (protection rules, blacklist, and whitelist), numbers of allowed and blocked accesses, and the allow and block policies that were frequently hit within a specified time range.
    • Policy Hits: Hits of a rule within a specified time range.
    • Visualizations: View the top 5 items blocked by rules within a specified period. For more information, see Table 1. Click a record to view the policy matching details. For details, see Table 2.
      Table 1 Policy assistant statistics parameters

      Parameter

      Description

      Top Policies By Hits

      Policies that match and block traffic.

      Top Blocked Outbound IP Addresses

      Blocked outbound IP addresses. You can click Source or Destination to view the source or destination IP addresses.

      Top Blocked Inbound IP Addresses

      Blocked inbound IP addresses. You can click Source or Destination to view the source or destination IP addresses.

      Top Blocked Destination Ports

      Blocked destination ports. You can click Outbound or Inbound to view ports in the corresponding direction.

      Top Blocked IP Address Regions

      Regions of blocked IP addresses. You can click Destination of outbound access or Source of inbound access to check IP addresses.

Viewing Inactive Policies on the Policy Assistant Page

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region.
  3. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  4. In the navigation pane on the left, choose Protection Policies > Access Control > Policy Assistant. The Policy Assistant page is displayed.
  5. Click the Inactive Policies tab.
  6. Check the policies that have not been hit or enabled for more than 1 week, 1 month, 3 months, or 6 months. Modify or delete the policies in time.

    • To view policy details, click View in the Operation column of a policy.

      On the Inactive Policies tab page of the policy assistant, if the Hits of a protection rule is 0, the Last Hit indicates the time when the protection rule was created.

    • To edit a policy, click its name. On the page that is displayed, edit the policy and click OK.
    • To delete a policy, click Delete in its Operation column. In the displayed dialog box, confirm the deletion information, enter DELETE, and click OK.
    • To export policies, click Export and select the data scope. The data will be exported to your local PC.

References