Updated on 2026-09-23 GMT+08:00

Managing Protection Rules

Scenario

After creating a protection rule, you can edit, copy, or delete it in the rule list. The default priority of the copy of a protection rule is 1 (highest priority). This section describes how to perform the following operations:

Viewing Protection Rules

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region.
  3. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  4. In the navigation pane, choose Internet Border Protection Rules or VPC Border Protection Rules under Protection Policies > Access Control.
  5. View protection rule information.

    • On the Protection Rules page, the following information about the current firewall instance is displayed:
      • Protection Rule Usage: It shows the number of existing protection rules and the allowed maximum number of rules.
      • Outbound: This parameter is displayed only for Internet border protection rules.

        It indicates the number of protection rules where the traffic direction is Outbound. You can click the number. The system will filter and display the rules of this type in the list below.

      • Inbound: This parameter is displayed only for Internet border protection rules.

        It indicates the number of protection rules where the traffic direction is Inbound. You can click the number. The system will filter and display the rules of this type in the list below.

      • Allowed: It indicates the number of protection rules where the protection action is Allow. You can click the number. The system will filter and display the rules of this type in the list below.
      • Blocked: It indicates the number of protection rules where the protection action is Block. You can click the number. The system will filter and display the rules of this type in the list below.
    • In the protection rule list, you can filter rules by traffic direction. You can also set filters for search.

      After the filtering is successful, you can click the save icon next to the filter box. In the dialog box that is displayed, enter a filter set name and click OK to save the current filter criteria as a quick filter set. This set will be displayed in the drop-down list for quick reuse.

    Table 1 Protection rule parameters

    Parameter

    Description

    Priority

    Priority of the rule.

    A smaller value indicates a higher priority.

    Name/Rule ID

    Custom rule name and ID

    If Not hit is displayed next to a rule name, it indicates the rule has not been hit in the past month. You can hover the cursor over Not hit to check the rule hits and the last hit time.

    Status

    Status of the rule. It can be enabled or disabled.

    Direction

    This parameter is displayed only for EIP and NAT rules.

    Traffic direction of the rule. The value can be Inbound or Outbound.

    Source

    The party that originates a session.

    Destination

    The recipient of a session.

    Service

    • Its value can be TCP, UDP, ICMP, or Any.
    • Source Port: Source ports to be allowed or blocked. You can configure a single port or consecutive port groups (example: 80-443).
    • Destination Port: Destination ports to be allowed or blocked.

      You can configure a single port or consecutive port groups (example: 80-443).

    Application

    Application type in the access traffic.

    Action

    • Allow: Allow the traffic to pass through the firewall.
    • Block: Block the traffic from passing through the firewall.

    Hits

    Total number of actions that have been triggered by the rule (since the last reset). For details, see Viewing Access Control Logs.

    If the number of hits is not 0, you can click the number to go to the Access Control Logs tab page of the Log Query page to view detailed log information. For details, see Viewing Access Control Logs.

    Tags

    Tag of a rule.

    By default, the preceding parameters are displayed. To move them or show other parameters, such as the creation time, modification time, and last used time, click the setting button in the upper right corner of the table.

Editing a Protection Rule

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region.
  3. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  4. In the navigation pane, choose Internet Border Protection Rules or VPC Border Protection Rules under Protection Policies > Access Control.
  5. In the row of a rule, click Edit in the Operation column.
  6. On the displayed page, edit the parameters as required.
  7. Click OK.

Copying a Protection Rule

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region.
  3. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  4. In the navigation pane, choose Internet Border Protection Rules or VPC Border Protection Rules under Protection Policies > Access Control.
  5. In the row of a rule, choose More > Copy in the Operation column.
  6. On the displayed page, modify the parameters and click OK.

    The default priority of a new protection rule is 1 (highest priority).

Enabling or Disabling a Protection Rule

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region.
  3. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  4. In the navigation pane, choose Internet Border Protection Rules or VPC Border Protection Rules under Protection Policies > Access Control.
  5. Enable or disable a protection rule.

    • To enable a protection rule, click in its Status column.

      To enable multiple protection rules, select the rules and click Enable above the list.

      When the rule status changes to , the rule has been applied.

    • Disabling a protection rule:
      1. In the Status column of a rule, click .

        To disable multiple protection rules, select the rules and click Disable above the list.

      2. In the displayed dialog box, click OK.

        If the rule status changes to , the rule has been disabled.

Deleting a Rule

Deleted rules cannot be restored. Exercise caution when performing this operation. After a rule is deleted, CFW will not control the traffic specified by the rule. Exercise caution when deleting a rule.

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region.
  3. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  4. In the navigation pane, choose Internet Border Protection Rules or VPC Border Protection Rules under Protection Policies > Access Control.
  5. In the row of a rule, choose More > Delete in the Operation column.

    To delete multiple protection rules, select the rules and click Delete above the list.

  6. If operation protection is not enabled, enter DELETE, and click OK in the displayed dialog box.

    If operation protection is enabled, select a verification mode, click Send Code, enter the code, and click OK.

References