Updated on 2026-08-21 GMT+08:00

Configuring Virtual Patching

Scenario

In network security protection, traditional methods of fixing high-risk vulnerabilities often require service restarts, which can lead to service interruptions and adversely impact user experience. CFW provides hot patches for IPS at the network layer to intercept high-risk remote attacks in real time and prevent service interruptions during vulnerability fixing.

  • Updated rules are added to the virtual patch library first. You can determine whether to add the rules to the basic protection library.
  • To add defense rules, enable this function to apply virtual patch rules. The protection action can be manually modified.

This section describes how to configure virtual patching defense.

Notes and Constraints

  • Intrusion prevention does not support decryption detection and defense for TLS- and SSL-encrypted traffic.

Impacts on Services

If IPS basic protection is enabled, a range of possible threats and suspicious traffic will be blocked. To change the protection mode, you are advised to enable the Observe mode and check false alarms for a period of time and then switch to the Intercept mode.

Enabling Virtual Patching

  1. Enable at least one type of traffic protection.

  2. Log in to the CFW console.
  3. Click in the upper left corner of the management console and select a region or project.
  4. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  5. In the navigation pane on the left, choose Protection Policies > Attack Defense > Intrusion Prevention.
  6. Ensure Basic Protection is enabled.
  7. In the Virtual Patching area, click the switch toggle button to enable protection.

Follow-up Operations

For details about the protection overview, see Event Center. For details about logs, see Viewing Attack Event Logs.

Related Operations

  • Updating virtual patches: Click Update Virtual Patch in the Virtual Patching area. In the displayed dialog box, click OK. The system will automatically start the update. After the update, you can view their details in 3 to 5 minutes.
  • Viewing virtual patch details: Click View Virtual Patch in the Virtual Patching area. On the displayed page, you can view the virtual patch rule details, including the rule name, risk level, and attack type.
  • Disabling virtual patching: Click the toggle button next to Virtual Patching. In the displayed dialog box, click OK.