Updated on 2026-09-14 GMT+08:00

Auto-protecting New EIPs

Scenario

CFW supports automatic protection for new EIPs. If auto-protection on new EIPs is enabled, CFW automatically synchronizes EIPs on the hour and enables protection for new EIPs. The traffic of the EIPs will be protected by the firewall.

Auto-protecting New EIPs

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  4. In the navigation pane on the left, choose Assets > EIPs. The EIPs page is displayed.
  5. In the Firewall Information area, enable Auto Protect New EIP. In the displayed dialog box, click OK.

    Figure 1 Automatic EIP protection
    If both automatic EIP protection and multi-account protection are enabled, pay attention to the following:
    • If multi-account protection is configured before automatic EIP protection is enabled, CFW will automatically synchronize and enable Internet border traffic protection for new EIPs of all accounts (including the current account and other accounts).
    • If multi-account protection is configured or the Querying the EIP List API is called after automatic EIP protection is enabled and automatic asset synchronization is complete, you need to manually enable EIP protection for other accounts.

Follow-up Operations

Once Internet border traffic protection is enabled, your service traffic is routed through CFW. By default, all traffic is allowed. You can view traffic trends or configure access control and attack defense policies for the Internet border firewall to better control the traffic between your cloud assets and the Internet.

Related Operations

  • Disabling protection: If you do not need to protect an EIP, you can disable its protection. For details, see Disabling Protection for an EIP.

    If EIP protection is disabled, CFW no longer protects the EIP traffic, and EIPs may be exposed to attacks. Exercise caution when performing this operation.

  • Exporting the EIP list: Click Export above the list and select an export scope.
  • Multi-account protection: To protect EIPs of other accounts, see Multi-Account Management.
  • One-click kill switch and restoration: To disable or restore EIP protection under a firewall, see One-click Kill Switch and One-click Restoration.