Managing Service Groups
Scenario
A service group is a collection of services (protocols, source ports, and destination ports). You can reference a service group in an access rule to implement unified traffic control for that group. The updates of the service group will be automatically synchronized to all the policies associated with it. This helps you quickly modify policies and avoid repeated configuration, improving O&M efficiency.
Notes and Constraints
- For adding a user-defined service group and services:
- A service group can have up to 64 services.
- A firewall instance can have up to 512 service groups.
- A firewall instance can have up to 900 services.
- You can only view predefined service groups, but cannot add services to it, or modify or delete it.
- The service group referenced by a protection rule cannot be deleted. Modify or delete the rule first.
Adding a User-defined Service Group
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane on the left, choose and click the Service Groups tab.
- On the User-defined Service Groups sub-tab, click Add Service Group. On the Add Service Group page, enter the service group information.
Table 1 Service group parameters Parameter
Description
Service Group Name
Name of a service group
Services
- Protocol: Select a protocol. Supported protocols include TCP, UDP, and ICMP.
- Source Port: Set the source port to be allowed or blocked. You can configure a single port or consecutive port groups (example: 80-443).
- Destination Port: Set the destination port to be allowed or blocked. You can configure a single port or consecutive port groups (example: 80-443).
- Description: Usage and application scenario of the service group
Description
Usage and application scenario
- Confirm the information and click OK.
A service group takes effect only after it is configured in a protection rule. For details about how to configure a protection rule, see Configuring Protection Rules to Block or Allow Internet Border Traffic, Configuring Protection Rules to Block or Allow VPC Border Traffic, Configuring Protection Rules to Block or Allow NAT Gateway Border Traffic.
Adding, Exporting, or Deleting Services in a User-defined Service Group
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane on the left, choose and click the Service Groups tab.
- On the User-defined Service Groups sub-tab, click the name of a service group. The service group details page is displayed.
- Add, export, or delete services in a user-defined service group.
Table 2 Adding, exporting, or deleting services in a user-defined service group Operation
Procedure
Adding a service to a user-defined service group
- Click Add Service. On the page that is displayed, enter the service information.
- Protocol: Its value can be TCP, UDP, or ICMP.
- Source Port: Set the source port to be allowed or blocked. You can configure a single port or consecutive port groups (example: 80-443).
If Protocol is set to ICMP, you do not need to specify any port number.
- Destination Port: Set the destination port to be allowed or blocked. You can configure a single port or consecutive port groups (example: 80-443).
If Protocol is set to ICMP, you do not need to specify any port number.
- Description: Enter the usage and application scenario of the service.
- To add multiple services, click Add.
- Confirm the information and click OK.
Exporting services in a user-defined service group
On the service group details page, click Export above the list and select the data scope. Data will be automatically exported to your local PC.
Deleting services in a user-defined service group
- On the service group details page, locate the row that contains the target service and click Delete in the Operation column.
To delete multiple services, select the target services and click Delete above the list.
- In the displayed dialog box, confirm the information and click OK.
- Click Add Service. On the page that is displayed, enter the service information.
Exporting or Deleting User-defined Service Groups
Deleted service groups cannot be restored. Exercise caution when performing this operation.
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane on the left, choose and click the Service Groups tab.
- Export or delete user-defined service groups.
- Export: Click Export above the service group list and select the data scope. The system automatically exports the data to your local PC.
- Delete:
- On the User-defined Service Groups tab page, click Delete in the Operation column of a service group.
To delete multiple service groups, select the target service groups and click Delete above the list.
- In the displayed dialog box, confirm the information, enter DELETE, and click OK.
- On the User-defined Service Groups tab page, click Delete in the Operation column of a service group.
Viewing a Predefined Service Group
CFW provides predefined service groups, including Web Service, Database, and Remote Login and Ping, suitable for protecting web services, databases, and servers, respectively.
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane on the left, choose and click the Service Groups tab.
- Click the Pre-defined Service Groups sub-tab and click the name of a service group. On the details page that is displayed, view the service group information.
- View the name, description, and added services of the predefined service group.
To export services in a predefined service group, click Export above the list and select the data scope. The system automatically exports the data to your local PC.
Related Operations
- Exporting service groups: Click Export above the list and select a data range.
- Batch deleting services: On the service group details page, select services, click Delete above the list, confirm the information, and click OK.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot