Using CFW Professional Edition to Protect Cloud Desktop SNAT and Inter-VPC Traffic
Scenarios
You can use CFW to centrally manage and protect all access traffic on the cloud desktop service plane, including public network access, inter-VPC access, and private line access.
Procedure
The following example shows how to use CFW professional edition to protect cloud desktop SNAT traffic. (The same networking can protect east-west and north-south traffic of cloud desktops.)
- Log in to the console.
- Click
in the upper left corner and choose Network > Virtual Private Cloud. The Virtual Private Cloud page is displayed. - Create a NAT transit VPC by referring to Creating a VPC with a Subnet.
As the VPC is used only for network forwarding, ensure that the CIDR block of the VPC does not conflict with that of the VPC where the desktop is located.
- Click
in the upper left corner and choose Network > NAT Gateway. The NAT Gateway page is displayed. - Buy a public NAT gateway by referring to Buying a Public NAT Gateway.
- In the Operation column of the NAT gateway, click Configure. The NAT gateway rule setting page is displayed.
- On the SNAT Rules page, click Add SNAT Rule to add a rule for forwarding traffic to the Internet.

- Click OK.
- Click
in the upper left corner and choose Network > Enterprise Router. The Enterprise Router page is displayed. - Create an enterprise router by referring to Creating an Enterprise Router.
- Click the newly created enterprise router to go to the details page.
- Click the Attachments tab and click Create Attachment to attach the Workspace VPC and NAT VPC to the enterprise router. (If no route is configured on the connection side, add the corresponding service route to the VPC route table.)
- Workspace VPC: Choose Tenant Configuration > Basic Settings on the Workspace console to view the VPC.
- NAT transit VPC: Obtain the value from 3.

- Click
, search for "CFW", and click CFW to access the CFW console. - Purchase a CFW instance (professional edition in this example) by referring to Purchasing and Modifying CFW. For details about the differences between different specifications, see CFW Functions.
- In the navigation pane, choose Assets > Inter-VPC Border Firewalls.
- Click Create Inter-VPC Firewall. The Create Inter-VPC Firewall page is displayed.
- Set Route Type to Enterprise Router and click Next.
- Select the enterprise router created in 10.
- Set a private network segment that does not conflict with the Workspace VPC.
- Click OK.
This CIDR block will be used to forward traffic to CFW. It cannot be modified once created. Note that:
- This CIDR block cannot overlap with the private network segment to be protected, or there may be routing conflicts.
- The CIDR blocks 10.1.0.0/16 and 10.6.0.0/16-10.7.0.0/16 are reserved for CFW.
- Click
, search for "Enterprise Router", and click Enterprise Router to access the Enterprise Router console. - Click the name of the created instance to go to the basic information page.
- Click the Route Tables tab, click the default route table defaultRouteTable, and click the Associations tab.
- Locate the CFW attachment that auto association of inter-VPC protection is enabled for, click Delete in the Operation column, and click OK.
- Click the Propagations tab, locate the propagation of the NAT transit VPC, click Delete in the Operation column, and click OK.
- On the Routes page, click Create Route to create a route that directs all traffic to CFW.

- On the Route Tables page, click Create Route Table.

- On the new route table, click the Associations tab and click Create Association.
- Attachment Type: CFW instance
- Attachment: Select a firewall name from the drop-down list.
- Click OK.

- On the new route table, click the Propagations tab and click Create Propagation.
- Attachment Type: VPC
- Attachment: Select the name of the Workspace VPC from the drop-down list.
- Click OK.

- On the new route table, click the Routes tab and click Create Route.
- Destination: 0.0.0.0/0
- Attachment Type: VPC
- Next Hop: the VPC of the NAT gateway
- Click OK.

- Click
in the service list, search for "VPC", and click VPC to access the VPC console. In the navigation pane, choose My VPCs. - In the row containing the Workspace VPC, click the number in the Route Table column to go to the default route table associated with the VPC. (In this example, only one VPC is associated with one route table.)
- Click the route table name. On the Workspace VPC route table details page, click Add Route to add a route rule to forward all access requests of the Workspace VPC to the enterprise router.

- Repeat 26 to 27, locate the row that contains the NAT transit VPC, and go to the default route table associated with the NAT transit VPC.
- Click the route table name. On the NAT transit VPC route table details page, click Add Route to add a route so that all traffic returning to the Workspace VPC goes back through the enterprise router.

- Click
, search for "CFW", and click CFW to access the CFW console. - In the navigation pane, choose Access Control > Internet Border Protection Rules. Then, click the NAT tab. (Note: To avoid redundant traffic filtering, do not enable the EIP rule if a NAT rule is enabled.)
- Click Add. In the displayed Add Rule dialog box, enter the protection information and configure the protection rule based on the actual service deployment. (In this example, Workspace denies access to the public network by default and allows access only to Huawei Cloud websites.)
- Configure a rule to block all traffic destined for the public network, as shown in Table 1.
Table 1 Rule parameters Parameter
Example
Description
Direction
SNAT
Direction of the protected traffic.
Source
Any
Origin of network traffic.
Destination
Any
Receiver of network traffic.
Service
Any
Protocol, source port, and destination port of network traffic.
Application
Any
Protection policy for application layer protocols.
Protection Action
Blocked
Action taken when traffic passes through the firewall.
- Add another rule to allow access to all Huawei Cloud websites, as shown in Table 2.

Table 2 Rule parameters Parameter
Example
Description
Direction
SNAT
Direction of the protected traffic.
Source
Any
Origin of network traffic.
Destination
Select Application Domain Name from the drop-down list and enter *.huaweicloud.com,huaweicloud.com,*.myhuaweicloud.com,*.hc-cdn.com,*.hc-cdn.cn.
Receiver of network traffic.
Note: You can use application domain name groups for centralized management.
Service
- Service: Service
- Protocol: TCP
- Source Port: 1-65535
- Destination Port: 1-65535
Protocol, source port, and destination port of network traffic.
Application
Select Application and choose HTTP and HTTPS from the drop-down list.
Protection policy for application layer protocols.
Protection Action
Allowed
Action taken when traffic passes through the firewall.
- In the navigation pane, choose Assets > Inter-VPC Border Firewalls, and set Firewall Status to Enabled.

- In the navigation pane, choose Log Audit > Log Query. Click the Access Control Logs tab. In the rows where Destination IP is a domain name matching huaweicloud.com, the corresponding Action is Allowed. For other traffic, the Action is Blocked.

Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot