Managing Protection Rules
Scenario
After creating a protection rule, you can edit, copy, or delete it in the rule list. The default priority of the copy of a protection rule is 1 (highest priority). This section describes how to perform the following operations:
Viewing Protection Rules
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane, choose Internet Border Protection Rules or VPC Border Protection Rules under .
- View protection rule information.
- On the Protection Rules page, the following information about the current firewall instance is displayed:
- Protection Rule Usage: It shows the number of existing protection rules and the allowed maximum number of rules.
- Outbound: This parameter is displayed only for Internet border protection rules.
It indicates the number of protection rules where the traffic direction is Outbound. You can click the number. The system will filter and display the rules of this type in the list below.
- Inbound: This parameter is displayed only for Internet border protection rules.
It indicates the number of protection rules where the traffic direction is Inbound. You can click the number. The system will filter and display the rules of this type in the list below.
- Allowed: It indicates the number of protection rules where the protection action is Allow. You can click the number. The system will filter and display the rules of this type in the list below.
- Blocked: It indicates the number of protection rules where the protection action is Block. You can click the number. The system will filter and display the rules of this type in the list below.
- In the protection rule list, you can filter rules by traffic direction. You can also set filters for search.
After the filtering is successful, you can click the save icon next to the filter box. In the dialog box that is displayed, enter a filter set name and click OK to save the current filter criteria as a quick filter set. This set will be displayed in the drop-down list for quick reuse.
Table 1 Protection rule parameters Parameter
Description
Priority
Priority of the rule.
A smaller value indicates a higher priority.
Name/Rule ID
Custom rule name and ID
If Not hit is displayed next to a rule name, it indicates the rule has not been hit in the past month. You can hover the cursor over Not hit to check the rule hits and the last hit time.
Status
Status of the rule. It can be enabled or disabled.
Direction
This parameter is displayed only for EIP and NAT rules.
Traffic direction of the rule. The value can be Inbound or Outbound.
Source
The party that originates a session.
Destination
The recipient of a session.
Service
- Its value can be TCP, UDP, ICMP, or Any.
- Source Port: Source ports to be allowed or blocked. You can configure a single port or consecutive port groups (example: 80-443).
- Destination Port: Destination ports to be allowed or blocked.
You can configure a single port or consecutive port groups (example: 80-443).
Application
Application type in the access traffic.
Action
- Allow: Allow the traffic to pass through the firewall.
- Block: Block the traffic from passing through the firewall.
Hits
Total number of actions that have been triggered by the rule (since the last reset). For details, see Viewing Access Control Logs.
If the number of hits is not 0, you can click the number to go to the Access Control Logs tab page of the Log Query page to view detailed log information. For details, see Viewing Access Control Logs.
Tags
Tag of a rule.
By default, the preceding parameters are displayed. To move them or show other parameters, such as the creation time, modification time, and last used time, click the setting button in the upper right corner of the table.
- On the Protection Rules page, the following information about the current firewall instance is displayed:
Editing a Protection Rule
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane, choose Internet Border Protection Rules or VPC Border Protection Rules under .
- In the row of a rule, click Edit in the Operation column.
- On the displayed page, edit the parameters as required.
- Click OK.
Copying a Protection Rule
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane, choose Internet Border Protection Rules or VPC Border Protection Rules under .
- In the row of a rule, choose More > Copy in the Operation column.
- On the displayed page, modify the parameters and click OK.
The default priority of a new protection rule is 1 (highest priority).
Enabling or Disabling a Protection Rule
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane, choose Internet Border Protection Rules or VPC Border Protection Rules under .
- Enable or disable a protection rule.
- To enable a protection rule, click
in its Status column. To enable multiple protection rules, select the rules and click Enable above the list.
When the rule status changes to
, the rule has been applied. - Disabling a protection rule:
- In the Status column of a rule, click
. To disable multiple protection rules, select the rules and click Disable above the list.
- In the displayed dialog box, click OK.
If the rule status changes to
, the rule has been disabled.
- In the Status column of a rule, click
- To enable a protection rule, click
Deleting a Rule
Deleted rules cannot be restored. Exercise caution when performing this operation. After a rule is deleted, CFW will not control the traffic specified by the rule. Exercise caution when deleting a rule.
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane, choose Internet Border Protection Rules or VPC Border Protection Rules under .
- In the row of a rule, choose More > Delete in the Operation column.
To delete multiple protection rules, select the rules and click Delete above the list.
- If operation protection is not enabled, enter DELETE, and click OK in the displayed dialog box.
If operation protection is enabled, select a verification mode, click Send Code, enter the code, and click OK.
References
- For details about how to add a protection rule, see Configuring Protection Rules to Block or Allow Internet Border Traffic, Configuring Protection Rules to Block or Allow VPC Border Traffic, Configuring Protection Rules to Block or Allow NAT Gateway Border Traffic.
- For details about how to batch add blacklist or whitelist items, see Configuring the Blacklist/Whitelist to Block or Allow Internet Border Traffic, Adding Blacklist or Whitelist Items to Block or Allow VPC Border Traffic, Adding Blacklist or Whitelist Items to Block or Allow NAT Gateway Border Traffic.
- Checking protection outcomes:
- Policy hits: For details about the protection overview, see Viewing Protection Information Using the Policy Assistant. For details about logs, see Viewing Attack Event Logs.
- For details about the traffic trend and statistics, see Traffic Center. For details about traffic records, see Log Query.
- For details about how to batch add protection policies, see Importing and Exporting Protection Policies.
- For details about how to adjust rule priority, see Adjusting the Priority of a Protection Rule.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot