Help Center/ Cloud Firewall/ Best Practices/ Allowing Internet Traffic Only to a Specified Port
Updated on 2024-09-23 GMT+08:00

Allowing Internet Traffic Only to a Specified Port

Application Scenarios

For security purposes, you need to allow traffic only from certain ports (such as ports 80 and 443) to access cloud resources.

This section describes how to configure CFW for refined management and control on cloud resources, allowing all EIPs to access port 80 of an EIP (xx.xx.xx.1).

Procedure

  1. Purchase the CFW standard or professional edition. For details, see Purchasing CFW.
  2. In the navigation pane on the left, click and choose Security & Compliance > Cloud Firewall. The Dashboard page will be displayed.
  3. (Optional) Switch firewall instance: Select a firewall from the drop-down list in the upper left corner of the page.
  4. Enable protection for the EIP (xx.xx.xx.1).

    1. In the navigation pane, choose Assets > EIPs. The EIPs page is displayed. The EIP information is automatically updated to the list.
    2. In the row of the EIP (xx.xx.xx.1), click Enable Protection in the Operation column.

  5. Configure protection rules.

    1. In the navigation pane, choose Access Control > Access Policies.
    2. Click Add Rule. On the Add Rule page, configure protection information and set other parameters as needed.
      Configure the following protection rules:
      • One of the rule blocks all traffic, as shown in Figure 1. The priority is the lowest.
        • Direction: Inbound
        • Source: Any
        • Destination: Any
        • Service: Any
        • Application: Any
        • Action: Block
        Figure 1 Blocking all traffic
      • The other rule allows the traffic to port 80 of the EIP (xx.xx.xx.1), as shown in Figure 2. The priority is the highest.
        • Direction: Inbound
        • Source: Any
        • Destination: Select IP address and enter xx.xx.xx.1.
        • Service: TCP/1-65535/80
        • Application: Any
        • Action: Allow
        Figure 2 Allowing access traffic to port 80 of xx.xx.xx.1

  6. View the rule hits in access control logs.

    In the navigation pane, choose Log Audit > Log Query. Click the Access Control Logs tab.

    In the rows where Destination IP is xx.xx.xx.1, the corresponding Action is Block.

References

For details about how to add other protection rules, see the parameter description in Adding a Protection Rule.