Updated on 2024-07-05 GMT+08:00

Purchasing a Yearly/Monthly Cloud Firewall

Yearly/Monthly is a prepaid billing mode and is cost-effective for long-term use.

You can purchase multiple firewalls in a region and assign them different resources and policies.

Prerequisites

The current account has the BSS Administrator and CFW FullAccess permissions.

Constraints

  • CFW can be used in the selected region only. To use CFW in another region, switch to the corresponding region and then purchase it. For details about the regions where CFW can be purchased, see Function Overview.

Editions

CFW can be billed in yearly/monthly (prepaid) or pay-per-use (postpaid) mode.
  • The yearly/monthly CFWs support the standard edition and professional edition.
  • The pay-per-use CFWs support the professional edition.

For details about the differences between editions, see Editions.

The application scenarios for different editions are as follows:
  • Standard edition

    Suitable for SMEs that need to defend against network intrusions and server compromises, or need to obtain Multi-Layer Protection Scheme (MLPS) certification.

  • Professional edition

    Suitable for large and medium-sized enterprises that need to defend against network intrusions and server compromises, control internal network security, or obtain Multi-Layer Protection Scheme (MLPS) certification.

Standard Edition Firewalls

  1. Log in to the management console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. In the navigation pane on the left, click and choose Security & Compliance > Cloud Firewall. The Dashboard page will be displayed.
  4. Click Buy CFW and configure parameters on the Buy CFW page. For more information, see Table 1.

    Table 1 Parameters for purchasing the standard edition CFW

    Parameter

    Description

    Billing Mode

    Yearly/Monthly

    Region

    Region where the CFW is to be purchased.

    NOTICE:

    CFWs can be used in the selected region only. To use a CFW in another region, switch to the corresponding region and then purchase it. For details about the regions where CFW is available, see Can CFW Be Used Across Clouds or Regions?

    Edition

    Select the standard edition.

    Engine

    Direct engine. You can implement fine-grained application control, for example, by using policies and limiting sessions. You can also take advantage of intrusion prevention, virus filtering, and defense functions to enhance access security, defend against attacks, and identify and control applications.

    Add EIP Protection Capacity

    (Optional) Number of additional EIPs to be protected. Value range: 0 to 2000.

    NOTE:

    By default, 20 public IP addresses are protected by the standard edition (included in the package fee). If you have 65 public IP addresses, you only need to enter 45.

    Add Peak Traffic Protection Capacity

    (Optional) Additional peak inbound or outbound traffic. The value range is 0 to 5000 Mbit/s per month. (The value must be an integer multiple of 5.)

    NOTE:
    • By default, up to 10 Mbit/s per month is protected by the standard edition (included in the package fee). If your protection traffic is 200 Mbit/s per month, you only need to enter 190 Mbit/s per month.
    • The protection traffic is determined based on the maximum inbound or outbound traffic, whichever is higher.

    Enterprise Project

    Select the enterprise project to which you belong from the drop-down list. The purchased CFW then belongs to that enterprise project and protects all resources in that project.

    This option is only available if you have logged in using an enterprise account, or if you have enabled enterprise projects. To use this function, Enable Enterprise Center. You can use an enterprise project to centrally manage your cloud resources and members by project.

    NOTE:

    Value default indicates the default enterprise project. Resources that are not allocated to any enterprise projects under your account are displayed in the default enterprise project.

    Firewall Name

    Firewall name.

    It must meet the following requirements:
    • Only letters (A to Z and a to z), numbers (0 to 9), spaces, and the following characters are allowed: -_
    • The value can contain 1 to 48 characters.

    Advanced Settings

    Tags: You can use a tag for multiple cloud resources. You are advised to predefine tags in TMS. For details, see Resource Tag Overview.

    If your organization has configured a tag policy for CFW, you need to add tags in compliance with the policy. If a tag does not comply with the tag policies, firewall instance creation may fail. Contact your organization administrator to learn more about tag policies.

    Required Duration

    Service duration.

    After selecting a duration, you can select Auto-renew. If you select and agree to service auto renewal, the system automatically generates a renewal order based on the subscription period and renews the service before it expires. Note the Auto-Renewal Rules when enabling auto-renewal.

  1. Confirm the purchase information and click Buy Now.
  2. Confirm the order details, select I have read and agreed to the Huawei Cloud Firewall Service Statement, and click Next.
  3. Select a payment method and pay for your order.

Professional Edition Firewalls

  1. Log in to the management console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. In the navigation pane on the left, click and choose Security & Compliance > Cloud Firewall. The Dashboard page will be displayed.
  4. Click Buy CFW and configure parameters on the Buy CFW page. For more information, see Table 2.

    Table 2 Parameters for purchasing a professional edition CFW

    Parameter

    Description

    Billing Mode

    Yearly/Monthly

    Region

    Region where the CFW is to be purchased.

    NOTICE:

    CFW can be used in the selected region only. To use CFW in another region, switch to the corresponding region and then purchase it. For details about the regions where CFW can be purchased, see Function Overview.

    Edition

    Select the professional edition.

    Engine

    Direct engine. You can implement fine-grained application control, for example, by using policies and limiting sessions. You can also take advantage of intrusion prevention, virus filtering, and defense functions to enhance access security, defend against attacks, and identify and control applications.

    Add EIP Protection Capacity

    (Optional) Number of additional EIPs to be protected. Value range: 0 to 2000.

    NOTE:

    By default, 20 public IP addresses are protected by the standard edition (included in the package fee). If you have 65 public IP addresses, you only need to enter 45.

    Add Peak Traffic Protection Capacity

    (Optional) Additional peak inbound or outbound traffic. The value range is 0 to 10000 Mbit/s per month. (The value must be an integer multiple of 5.)

    NOTE:
    • By default, up to 10 Mbit/s per month is protected by the standard edition (included in the package fee). If your protection traffic is 200 Mbit/s per month, you only need to enter 190 Mbit/s per month.
    • The protection traffic is determined based on the maximum inbound or outbound traffic, whichever is higher.

    Added VPCs

    (Optional) Select the number of VPCs to be expanded. The value ranges from 0 to 500.

    NOTE:
    • Only the professional edition supports inter-VPC protection.
    • By default, 2 VPCs are protected by the professional edition (included in the package fee). If you have 3 VPCs, you only need to enter 1.
    • For each VPC you add, the protected peak traffic increases by 200 Mbit/s.

    Enterprise Project

    Select the enterprise project to which you belong from the drop-down list. The purchased CFW then belongs to that enterprise project and protects all resources in that project.

    This option is only available if you have logged in using an enterprise account, or if you have enabled enterprise projects. To use this function, Enable Enterprise Center. You can use an enterprise project to centrally manage your cloud resources and members by project.

    NOTE:

    Value default indicates the default enterprise project. Resources that are not allocated to any enterprise projects under your account are displayed in the default enterprise project.

    Firewall Name

    Firewall name.

    It must meet the following requirements:
    • Only letters (A to Z and a to z), numbers (0 to 9), spaces, and the following characters are allowed: -_
    • The value can contain 1 to 48 characters.

    Advanced Settings

    Tags: You can use a tag for multiple cloud resources. You are advised to predefine tags in TMS. For details, see Resource Tag Overview.

    If your organization has configured a tag policy for CFW, you need to add tags in compliance with the policy. If a tag does not comply with the tag policies, firewall instance creation may fail. Contact your organization administrator to learn more about tag policies.

    Required Duration

    Service duration.

    After selecting a duration, you can select Auto-renew. If you select and agree to service auto renewal, the system automatically generates a renewal order based on the subscription period and renews the service before it expires. Note the Auto-Renewal Rules when enabling auto-renewal.

  1. Confirm the purchase information and click Buy Now.
  2. Confirm the order details, select I have read and agreed to the Huawei Cloud Firewall Service Statement, and click Next.
  3. Select a payment method and pay for your order.

Effective Conditions

Your CFW instance is purchased when your instance edition and its quota information are shown in the upper left corner of the management console.