Scenario
CFW alarm notification monitors the running status and risks of CFW in real time. When detecting attacks, unprotected EIPs, or other risks, the service sends SMS or email notifications to specified recipients, helping them detect and handle threats in time and enhance asset security.
Simple Message Notification (SMN) is a paid service. For details, see Product Pricing Details.
Alarm Notification Items
CFW supports the following alarm notification items:
Table 1 Alarm notification items | Alarm Notification Item | Description |
| Attack Alarm | When CFW detects an intrusion (such as port scan, SQL injection, or malicious code attack) and the preset triggering conditions are met, an alarm notification is sent. |
| High Traffic Warning | If the peak traffic passing through CFW reaches a certain percentage (for example, 70%, 80%, or 90%) of the purchased traffic processing capacity, and such excess occurs three or more times within 5 minutes, an alarm notification will be sent. (The notification is sent only once every day.) |
| EIP Not Protected | If CFW detects unprotected EIPs under your account, it will send an alarm notification once a day. (The notification is sent only once every day.) |
| Abnormal External Connection Alarm | If CFW detects suspicious behavior of IP addresses or domain names that may be used for external connections and the trigger conditions are met, it will send an alarm notification. Abnormal external connection alarms are supported only in certain regions. For details, see the regions displayed on the console. |
Setting Alarm Notifications
You can set the alarm notification time, trigger condition, and recipient group, so that CFW can send notifications to recipients in the specified period of time using the method you configure (for example, by email or SMS message).
Attack Alarm
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane, choose System Management > Notifications.
- In the Operation column of the Attack alarm, click Edit. On the notification item settings page that is displayed, configure notification parameters.
Table 2 Attack alarm parameters | Parameter | Description |
| Description | An alarm is triggered if an intrusion prevention event occurs. |
| Level | Select the risk levels that trigger notifications. The options are Serious, High, Medium, and Low. Multiple options can be selected. For example, if you select High and Medium, CFW will notify you by SMS message or email when detecting an intrusion with a high- or medium-level risk. |
| Notification Time | Select a time range for sending notifications. CFW sends notifications only within the alarm notification period. If an exception is detected outside this period, no notifications will be sent. |
| Trigger Condition | Configure the trigger condition. Alarm notifications are sent if the number of attacks is at least equal to the threshold configured for a certain period. |
| Recipient Group | Select a topic from the drop-down list to configure the endpoints for receiving alarm notifications. To create a topic, click View Topic to go to the SMN console. Perform the following operations: - Create a topic.
- Add one or more subscriptions to the topic. You will need to provide a phone number, email address, or HTTP/HTTPS endpoint to receive alarm notifications. For details, see Adding a Subscription.
- Confirm the subscription.
|
- Click OK.
- In the Status column of Attack alarm, click
to enable it. The notification settings take effect immediately after being modified.
High Traffic Warning
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane, choose System Management > Notifications.
- In the Operation column of the High Traffic Warning alarm, click Edit. On the notification item settings page that is displayed, configure notification parameters.
Table 3 High traffic warning parameters | Parameter | Description |
| Description | An alarm is generated if the traffic reaches the specified percentage of the traffic processing capability you have purchased. |
| Level | Select a percentage. When the maximum peak inbound or outbound traffic reaches the percentage of the traffic processing capability you have purchased, an alarm notification is triggered. For example, you can select 70%, 80%, or 90%. If this parameter is set to 80%, an alarm notification is sent when the used traffic reaches 80% of the purchased traffic. |
| Notification Time | Select a time range for sending notifications. CFW sends notifications only within the alarm notification period. If an exception is detected outside this period, no notifications will be sent. |
| Trigger Condition | Once a day |
| Recipient Group | Select a topic from the drop-down list to configure the endpoints for receiving alarm notifications. To create a topic, click View Topic to go to the SMN console. Perform the following operations: - Create a topic.
- Add one or more subscriptions to the topic. You will need to provide a phone number, email address, or HTTP/HTTPS endpoint to receive alarm notifications. For details, see Adding a Subscription.
- Confirm the subscription.
|
- Click OK.
- In the Status column of High Traffic Warning, click
to enable it. The notification settings take effect immediately after being modified.
EIP Not Protected
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane, choose System Management > Notifications.
- In the Operation column of the EIP Not Protected alarm, click Edit. On the notification item settings page that is displayed, configure notification parameters.
Table 4 Parameters of the alarm EIP Not Protected | Parameter | Description |
| Description | This alarm indicates that there are unprotected EIPs. |
| Notification Time | Select a time range for sending notifications. CFW sends notifications only within the alarm notification period. If an exception is detected outside this period, no notifications will be sent. |
| Trigger Condition | Once a day |
| Recipient Group | Select a topic from the drop-down list to configure the endpoints for receiving alarm notifications. To create a topic, click View Topic to go to the SMN console. Perform the following operations: - Create a topic.
- Add one or more subscriptions to the topic. You will need to provide a phone number, email address, or HTTP/HTTPS endpoint to receive alarm notifications. For details, see Adding a Subscription.
- Confirm the subscription.
|
- Click OK.
- In the Status column of EIP Not Protected, click
to enable it. The notification settings take effect immediately after being modified.
Abnormal External Connection Alarm
- Log in to the CFW console.
- Click
in the upper left corner of the management console and select a region or project. - (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
- In the navigation pane, choose System Management > Notifications.
- In the Operation column of the Abnormal External Connection Alarm, click Edit. On the notification item settings page that is displayed, configure notification parameters.
Table 5 Parameters of Abnormal External Connection Alarm | Parameter | Description |
| Description | If the service detects suspicious behaviors of IP addresses or domain names that may be used for external connections and the trigger conditions are met, it will send an alarm notification. |
| Notification Time | Select a time range for sending notifications. CFW sends notifications only within the alarm notification period. If an exception is detected outside this period, no notifications will be sent. |
| Trigger Condition | Configure the trigger condition. Alarm notifications are sent if the number of abnormal external connections is at least equal to the threshold configured for a certain period. |
| Recipient Group | Select a topic from the drop-down list to configure the endpoints for receiving alarm notifications. To create a topic, click View Topic to go to the SMN console. Perform the following operations: - Create a topic.
- Add one or more subscriptions to the topic. You will need to provide a phone number, email address, or HTTP/HTTPS endpoint to receive alarm notifications. For details, see Adding a Subscription.
- Confirm the subscription.
|
- Click OK.
- After confirming that the information is correct, click
in the column of the row where the Abnormal External Connection Alarm is located to enable this function. The notification settings take effect immediately after being modified.
Related Operations
If there are unprotected EIPs that do not need to trigger alarms, you can add them to the alarm whitelist to reduce invalid alarms, alleviating the impact on O&M or other functions. The operations are as follows:
- In the Operation column of the EIP Not Protected alarm, click Add to Alarm Whitelist.
- On the displayed page, select the target EIP and add it to the list on the right.
- Click OK.
After the EIP is added to the whitelist, no alarm notifications will be sent even if the EIP is not protected.