Help Center/ Cloud Firewall/ User Guide/ Access Control/ Managing ACL Policies/ Importing and Exporting Protection Policies
Updated on 2026-08-21 GMT+08:00

Importing and Exporting Protection Policies

Scenario

You can add and export protection rules, blacklist/whitelist items, IP address groups, domain name groups, and service groups in batches.

Notes and Constraints

  • To import and export VPC border protection policies, use the Professional edition.
  • For policy imports, each sheet supports up to 640 rules or members.

Importing Protection Rules in Batches

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  4. In the navigation pane, choose Internet Border Protection Rules or VPC Border Protection Rules under Protection Policies > Access Control.
  5. Click Import/Export Policy in the upper right corner of the page.
  6. Click Download Template to download the rule import template to the local host.
  7. Configure protection policy information as required.

  8. After filling in the template, click Import Rule to import the template.

    • Rule import takes several minutes.
    • During rule import, you cannot add, edit, or delete access policies, IP address groups, and service groups.
    • The priority of the imported policies is lower than that of the created policies.

  9. Click Import/Export Policy in the upper right corner of the page to check the status of the rule import task. If the Status is Imported, the import succeeded.
  10. Return to the protection rule list to view the imported protection rule.

    By default, the priority of imported rules is lower than that of manually added rules.

Exporting Protection Rules in Batches

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  4. In the navigation pane, choose Internet Border Protection Rules or VPC Border Protection Rules under Protection Policies > Access Control.
  5. Click Import/Export Policy in the upper right corner of the page.
  6. Click Export Rule.

    If the task status changes to Exported successfully, you can click Download to download the exported protection rules to the local PC.

Parameters for Importing a Rule Template

Fill in the template by referring to the following parameter descriptions.

References