Auto-protecting New EIPs
Scenario
CFW supports automatic protection for new EIPs. If auto-protection on new EIPs is enabled, CFW automatically synchronizes EIPs on the hour and enables protection for new EIPs. The traffic of the EIPs will be protected by the firewall.
Auto-protecting New EIPs
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane on the left, choose . The EIPs page is displayed.
- In the Firewall Information area, enable Auto Protect New EIP. In the displayed dialog box, click OK. Figure 1 Automatic EIP protection
If both automatic EIP protection and multi-account protection are enabled, pay attention to the following:- If multi-account protection is configured before automatic EIP protection is enabled, CFW will automatically synchronize and enable Internet border traffic protection for new EIPs of all accounts (including the current account and other accounts).
- If multi-account protection is configured or the Querying the EIP List API is called after automatic EIP protection is enabled and automatic asset synchronization is complete, you need to manually enable EIP protection for other accounts.
Follow-up Operations
Once Internet border traffic protection is enabled, your service traffic is routed through CFW. By default, all traffic is allowed. You can view traffic trends or configure access control and attack defense policies for the Internet border firewall to better control the traffic between your cloud assets and the Internet.
- View traffic trends and logs.
- View the traffic trends and statistics of CFW. For details, see Traffic Center.
- View all traffic logs of CFW. For details, see Viewing Traffic Logs.
- Configure protection rules for refined traffic control.
After protection is enabled, all traffic is allowed by default. CFW will block traffic based on the policies you configure.
- Allow or block traffic using protection rules. For details, see Configuring Protection Rules to Block or Allow Internet Border Traffic.
- Allow or block traffic using the blacklist and whitelist. For details, see Configuring the Blacklist/Whitelist to Block or Allow Internet Border Traffic.
- Defend against network attacks: Configure intrusion prevention to handle network attacks. For details, see Configuring Basic IPS Protection.
Related Operations
- Disabling protection: If you do not need to protect an EIP, you can disable its protection. For details, see Disabling Protection for an EIP.
If EIP protection is disabled, CFW no longer protects the EIP traffic, and EIPs may be exposed to attacks. Exercise caution when performing this operation.
- Exporting the EIP list: Click Export above the list and select an export scope.
- Multi-account protection: To protect EIPs of other accounts, see Multi-Account Management.
- One-click kill switch and restoration: To disable or restore EIP protection under a firewall, see One-click Kill Switch and One-click Restoration.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot