Viewing Outbound Traffic
Scenario
Outbound traffic analysis visualizes outbound traffic flowing from EIPs protected by the current firewall instance to the Internet. This capability helps you track outbound traffic trends, access destinations, targeted destination ports, and application distribution. With these insights, O&M personnel can quickly identify abnormal traffic and trace suspicious external connections. Additionally, the platform supports one-click blocking of high-risk destination IP addresses and data export for archiving, serving multiple operational needs including bandwidth capacity evaluation, routine security inspections, and graded protection security compliance audits.
This section describes how to view outbound traffic information.
Specification Limitations
- The data is collected from sessions. The statistics of a session is reported only after it is terminated.
- Traffic data is reported collectively after a session terminates. Consequently, persistent connections may experience a minor data display latency rather than real-time refreshes.
- Supported time ranges span from 5 minutes to 7 days. The system automatically adjusts the data aggregation granularity based on your selection. Custom intervals must be at least 5 minutes.
- To view data of private network assets initiating Internet connections, enable the VPC border firewall in the CFW professional edition. For details, see VPC border firewall.
- If intelligence-related tags (all intelligence tags or non-empty intelligence tags) are used for filtering on the External IP Addresses and External Domain Names tab pages, up to 1,000 records can be displayed.
Viewing the Outbound Traffic Dashboard
- Enable EIP protection, and ensure that existing traffic passes through the EIP.
For details about how to enable EIP protection, see Enabling Internet Border Traffic Protection.
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane, choose .
- On the Statistics Dashboard page of outbound traffic, check the traffic passing through the firewall within a time range, from 5 minutes to 7 days.
- Traffic Dashboard: Information about the highest traffic when internal servers access the Internet. Figure 1 Outbound traffic - traffic dashboard
- Outbound Traffic: Outbound request traffic and response traffic. The traffic statistics of up to 30 EIPs can be queried at a time.
The data displayed is the average bits per second (bps) of the sessions ended at the specified time in traffic logs.
Figure 2 Outbound traffic
Table 1 Value description Time Range
Value
Last 1 hour
Average value within every minute
Last 24 hours
Average value within every 5 minutes
Last 7 days
Average value within every hour
Custom
- 5 minutes to 6 hours: average value within every minute
- 6 hours (included) to 3 days: average value within every 5 minutes
- 3 (included) to 7 days (included): average value within every 30 minutes
- Visualizations: View the top 5 items ranked by specific parameters of outbound traffic within a specified period. For more information, see Table 2. You can click a data record to view the traffic details. A maximum of 50 data records can be viewed. Figure 3 Outbound traffic - visualized statistics
Table 2 Outbound traffic parameters Parameter
Description
Top Destination IP Addresses
Destination IP addresses of outbound traffic.
Top Destination Regions
Geographical locations of the destination IP addresses of outbound traffic.
Top Accessed Domain Names
Domain name information about outbound traffic.
Top Access Source IP Addresses
Source IP addresses of outbound traffic.
TOP Access Ports
Destination ports of outbound traffic.
Top Application Distribution
Application information about outbound traffic.
- Traffic Dashboard: Information about the highest traffic when internal servers access the Internet.
Analyzing External IP Address
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane on the left, choose . Click the External IP Addresses tab page.
- View the traffic information about the destination IP addresses within a specified period.
- The table shows the top 1,000 records with the highest access traffic. Each record includes the top five ports and applications with the highest access traffic.
- To block the traffic from an IP address, click Add to Blacklist in the Operation column to add it to the blacklist. CFW will directly block traffic from it.
- To export the external IP address list, click Export above the list and set the scope of data. The data will be automatically exported to the local PC.
Figure 4 External IP addresses
Analyzing External Domain Names
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane on the left, choose . Click the External Domain Names tab page.
- View the domain names within a specified period.
- The table shows the top 1,000 records with the highest access traffic. Each record includes the top five ports and applications with the highest access traffic.
- To export the external domain name list, click Export above the list and set the scope of data. The data will be automatically exported to the local PC.
Figure 5 External domain names
Analyzing Assets Initiating Internet Connections
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane on the left, choose . Click the Assets Initiating Internet Connections tab page.
- View the traffic information about the source EIPs within a specified period.
- The table shows the top 50 records with the highest access traffic. Each record includes the top five ports and applications with the highest access traffic.
- To export the list of assets initiating Internet connections, click Export above the list and set the scope of data. The data will be automatically exported to the local PC.
Figure 6 Assets initiating Internet connections
Analyzing Assets Initiating Private Network Connections
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane on the left, choose . Click the Assets Initiating Private Connections tab page.
- View the traffic of private source IP addresses within the specified time range.
- The table shows the top 50 records with the highest access traffic. Each record includes the top five ports and applications with the highest access traffic.
- To export the list of assets initiating private network connections, click Export above the list and set the scope of data. The data will be automatically exported to the local PC.
Figure 7 Assets initiating private network connections
Private IP address information is visible only to users who enable the VPC border firewall in the CFW professional edition.
References
- For details about how to view the statistics about the traffic from the Internet to the EIPs on the cloud, see Viewing Inbound Traffic.
- For details about how to check abnormal traffic, see What Can I Do If Services Cannot Be Accessed After a Policy Is Configured on CFW?
- For details about what to do when service traffic exceeds the protection bandwidth, see What Do I Do If My Service Traffic Exceeds the Protection Bandwidth?
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot