Updated on 2025-09-29 GMT+08:00

Configuring a NAT Protection Rule

After verifying the traffic flow, configure protection rules so that the CFW can allow or block traffic accordingly.

Configuring a NAT Protection Rule

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. (Optional) Switch to another firewall instance. Select a firewall from the drop-down list in the upper left corner of the page.
  4. In the navigation pane, choose Access Control > Internet Border Protection Rules.
  5. On the Protection Rules tab page, click the NAT sub-tab, and click Add Rule. On the Add Rule page, configure the key parameters as follows:

    • Rule Type: NAT
    • Direction: SNAT
    • Source: Select IP address. Enter a private IP address.
    • Destination: Select IP address (and enter a public IP address) or Domain name/Domain name group.
    • Application: Any

  6. Click OK.