Configuring Virtual Patching
Scenario
In network security protection, traditional methods of fixing high-risk vulnerabilities often require service restarts, which can lead to service interruptions and adversely impact user experience. CFW provides hot patches for IPS at the network layer to intercept high-risk remote attacks in real time and prevent service interruptions during vulnerability fixing.
- Updated rules are added to the virtual patch library first. You can determine whether to add the rules to the basic protection library.
- To add defense rules, enable this function to apply virtual patch rules. The protection action can be manually modified.
This section describes how to configure virtual patching defense.
Notes and Constraints
- Intrusion prevention does not support decryption detection and defense for TLS- and SSL-encrypted traffic.
Impacts on Services
If IPS basic protection is enabled, a range of possible threats and suspicious traffic will be blocked. To change the protection mode, you are advised to enable the Observe mode and check false alarms for a period of time and then switch to the Intercept mode.
Enabling Virtual Patching
- Enable at least one type of traffic protection.
- For details about how to enable EIP traffic protection, see Enabling Internet Border Traffic Protection.
- For details about how to enable VPC traffic protection, see Enabling VPC Border Traffic Protection.
- For details about how to enable traffic protection for private IP addresses, see Enabling NAT Gateway Traffic Protection.
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane on the left, choose .
- Ensure Basic Protection is enabled.
- In the Virtual Patching area, click the switch toggle button to enable protection.
Follow-up Operations
For details about the protection overview, see Event Center. For details about logs, see Viewing Attack Event Logs.
Related Operations
- Updating virtual patches: Click Update Virtual Patch in the Virtual Patching area. In the displayed dialog box, click OK. The system will automatically start the update. After the update, you can view their details in 3 to 5 minutes.
- Viewing virtual patch details: Click View Virtual Patch in the Virtual Patching area. On the displayed page, you can view the virtual patch rule details, including the rule name, risk level, and attack type.
- Disabling virtual patching: Click the toggle button next to Virtual Patching. In the displayed dialog box, click OK.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot