Help Center/ Cloud Firewall/ User Guide/ Traffic Analysis/ Viewing Outbound Traffic
Updated on 2026-07-15 GMT+08:00

Viewing Outbound Traffic

Scenario

Outbound traffic analysis visualizes outbound traffic flowing from EIPs protected by the current firewall instance to the Internet. This capability helps you track outbound traffic trends, access destinations, targeted destination ports, and application distribution. With these insights, O&M personnel can quickly identify abnormal traffic and trace suspicious external connections. Additionally, the platform supports one-click blocking of high-risk destination IP addresses and data export for archiving, serving multiple operational needs including bandwidth capacity evaluation, routine security inspections, and graded protection security compliance audits.

This section describes how to view outbound traffic information.

Specification Limitations

  • The data is collected from sessions. The statistics of a session is reported only after it is terminated.
  • Traffic data is reported collectively after a session terminates. Consequently, persistent connections may experience a minor data display latency rather than real-time refreshes.
  • Supported time ranges span from 5 minutes to 7 days. The system automatically adjusts the data aggregation granularity based on your selection. Custom intervals must be at least 5 minutes.
  • To view data of private network assets initiating Internet connections, enable the VPC border firewall in the CFW professional edition. For details, see VPC border firewall.
  • If intelligence-related tags (all intelligence tags or non-empty intelligence tags) are used for filtering on the External IP Addresses and External Domain Names tab pages, up to 1,000 records can be displayed.

Viewing the Outbound Traffic Dashboard

  1. Enable EIP protection, and ensure that existing traffic passes through the EIP.

    For details about how to enable EIP protection, see Enabling Internet Border Traffic Protection.

  2. Log in to the CFW console.
  3. Click in the upper left corner of the management console and select a region or project.
  4. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  5. In the navigation pane, choose Traffic Analysis > Outbound Traffic.
  6. On the Statistics Dashboard page of outbound traffic, check the traffic passing through the firewall within a time range, from 5 minutes to 7 days.

    • Traffic Dashboard: Information about the highest traffic when internal servers access the Internet.
      Figure 1 Outbound traffic - traffic dashboard
    • Outbound Traffic: Outbound request traffic and response traffic. The traffic statistics of up to 30 EIPs can be queried at a time.

      The data displayed is the average bits per second (bps) of the sessions ended at the specified time in traffic logs.

      Figure 2 Outbound traffic
      Table 1 Value description

      Time Range

      Value

      Last 1 hour

      Average value within every minute

      Last 24 hours

      Average value within every 5 minutes

      Last 7 days

      Average value within every hour

      Custom

      • 5 minutes to 6 hours: average value within every minute
      • 6 hours (included) to 3 days: average value within every 5 minutes
      • 3 (included) to 7 days (included): average value within every 30 minutes
    • Visualizations: View the top 5 items ranked by specific parameters of outbound traffic within a specified period. For more information, see Table 2. You can click a data record to view the traffic details. A maximum of 50 data records can be viewed.
      Figure 3 Outbound traffic - visualized statistics
      Table 2 Outbound traffic parameters

      Parameter

      Description

      Top Destination IP Addresses

      Destination IP addresses of outbound traffic.

      Top Destination Regions

      Geographical locations of the destination IP addresses of outbound traffic.

      Top Accessed Domain Names

      Domain name information about outbound traffic.

      Top Access Source IP Addresses

      Source IP addresses of outbound traffic.

      TOP Access Ports

      Destination ports of outbound traffic.

      Top Application Distribution

      Application information about outbound traffic.

Analyzing External IP Address

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  4. In the navigation pane on the left, choose Traffic Analysis > Outbound Traffic. Click the External IP Addresses tab page.
  5. View the traffic information about the destination IP addresses within a specified period.

    • The table shows the top 1,000 records with the highest access traffic. Each record includes the top five ports and applications with the highest access traffic.
    • To block the traffic from an IP address, click Add to Blacklist in the Operation column to add it to the blacklist. CFW will directly block traffic from it.
    • To export the external IP address list, click Export above the list and set the scope of data. The data will be automatically exported to the local PC.
    Figure 4 External IP addresses

Analyzing External Domain Names

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  4. In the navigation pane on the left, choose Traffic Analysis > Outbound Traffic. Click the External Domain Names tab page.
  5. View the domain names within a specified period.

    • The table shows the top 1,000 records with the highest access traffic. Each record includes the top five ports and applications with the highest access traffic.
    • To export the external domain name list, click Export above the list and set the scope of data. The data will be automatically exported to the local PC.
    Figure 5 External domain names

Analyzing Assets Initiating Internet Connections

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  4. In the navigation pane on the left, choose Traffic Analysis > Outbound Traffic. Click the Assets Initiating Internet Connections tab page.
  5. View the traffic information about the source EIPs within a specified period.

    • The table shows the top 50 records with the highest access traffic. Each record includes the top five ports and applications with the highest access traffic.
    • To export the list of assets initiating Internet connections, click Export above the list and set the scope of data. The data will be automatically exported to the local PC.
    Figure 6 Assets initiating Internet connections

Analyzing Assets Initiating Private Network Connections

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  4. In the navigation pane on the left, choose Traffic Analysis > Outbound Traffic. Click the Assets Initiating Private Connections tab page.
  5. View the traffic of private source IP addresses within the specified time range.

    • The table shows the top 50 records with the highest access traffic. Each record includes the top five ports and applications with the highest access traffic.
    • To export the list of assets initiating private network connections, click Export above the list and set the scope of data. The data will be automatically exported to the local PC.
    Figure 7 Assets initiating private network connections

    Private IP address information is visible only to users who enable the VPC border firewall in the CFW professional edition.

References