Help Center/ Cloud Firewall/ User Guide/ CFW Protection/ Enabling Internet Border Traffic Protection
Updated on 2026-09-14 GMT+08:00

Enabling Internet Border Traffic Protection

Scenario

CFW protects Internet border traffic by protecting EIPs. It controls the inbound and outbound traffic between cloud assets and the Internet, reducing the exposure of public network assets and minimizing traffic security risks.

This section describes the concepts related to Internet border firewalls and how to enable Internet border traffic protection.

What Is Internet Border Traffic?

Internet border traffic, a type of north-south traffic, is exchanged between cloud assets (both IPv4 and IPv6) and the Internet. It includes inbound traffic (from the Internet to cloud assets) and outbound traffic (from cloud assets to the Internet).

Direction

Definition

Protection Focus

Scenario

Inbound traffic

The Internet proactively accesses cloud assets.

Vulnerability exploits, web attacks, application-layer DDoS attacks, and password attacks

Web, API, and remote O&M access

Outbound traffic

Cloud assets proactively access the Internet.

Trojan Command and Control (C2) communication, phishing, access control, and other suspicious behaviors

Software updates, third-party API calls, and outbound data transfers

Once protection is enabled, your service traffic is routed through CFW. By default, all traffic is allowed. For granular traffic control, you can configure access control policies or modify the Intrusion Prevention System (IPS) mode based on your security requirements. CFW will inspect, block, or allow traffic based on your configuration, safeguarding traffic between your cloud assets and the Internet.

Figure 1 Internet border traffic protection

Introduction to Internet Border Traffic Protection

Protected Objects

ECSs, NAT gateways, ELBs, and other resources that are bound to EIPs

Protection Specifications

The Internet border protection specifications include the number of protected EIPs and the Internet border protection bandwidth.

Table 1 Internet border firewall protection specifications

Protection Specifications

Description

Standard Edition

Professional Edition

Protected EIPs

The total number of EIPs that can be protected by the current firewall instance.

20

It can be increased to 2,000.

For details, see Modifying CFW Extended Packages.

  • Yearly/Monthly: 50

    It can be increased to 2,000.

  • Pay-per-use: 1,000 (fixed)

    It cannot be increased.

Internet Border Protection Bandwidth

The maximum Internet border traffic that can be protected by the current firewall instance.

The value is the maximum inbound or outbound traffic.

Peak: 10 Mbit/s

It can be increased to 50,000 Mbit/s.

For details, see Modifying CFW Extended Packages.

  • Yearly/Monthly: Up to 50 Mbit/s

    It can be increased to 50,000 Mbit/s.

  • Pay-per-use: 1 Gbit/s (quota for Internet and VPC borders)

    If you need higher protection bandwidth, submit a service ticket.

Constraints

  • An EIP can only be protected by one firewall instance.
  • By default, a firewall instance only protects the EIPs of the current account. To protect EIPs of other accounts, you need to enable multi-account management. For details, see Multi-Account Management.
    If both automatic EIP protection and multi-account protection are enabled, pay attention to the following:
    • If multi-account protection is configured before automatic EIP protection is enabled, CFW will automatically synchronize and enable Internet border traffic protection for new EIPs of all accounts (including the current account and other accounts).
    • If multi-account protection is configured or the Querying the EIP List API is called after automatic EIP protection is enabled and automatic asset synchronization is complete, you need to manually enable EIP protection for other accounts.
  • Before unsubscribing from or releasing a protected EIP, you must disable its protection on the firewall page first. For details, see Disabling Protection for an EIP.

Impacts on Services

Before enabling EIP protection, check whether there is any protection rule or blacklist that blocks all traffic.

  • If protection is enabled for an EIP, such a protection rule or blacklist will take effect and block all the traffic of the EIP. This may interrupt services. Before enabling protection, check for persistent connections and services that do not support session reestablishment. If any, handle them first.

    For details about how to edit a protection rule, see Managing Protection Rules. For details about how to edit a blacklist, see Managing the Blacklist and the Whitelist.

  • If no protection rule or blacklist is configured to block all traffic, enabling or disabling EIP protection will not interrupt services.

Enabling Internet Border Traffic Protection

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  4. In the navigation pane on the left, choose Assets > EIPs. The EIPs page is displayed.

    The EIP information (IPv4 and IPv6) is automatically updated to the list.

  5. Enable protection for EIPs.

    An EIP can be protected by only one firewall.

    • Individual EIP: In the row of the target EIP, click Enable Protection in the Operation column. In the displayed dialog box, confirm the information and click Bind and Enable.
    • Multiple EIPs: Select the EIPs you want to protect and click Enable Protection above the list. In the displayed dialog box, confirm the information and click Bind and Enable.

    If Protected is displayed in the Protection Status column of the EIP, the protection has been enabled.

    After protection is enabled for an EIP, the system allows all traffic by default. That is, the default action of the access control policy is Allow.

Auto-protecting New EIPs

If auto-protection on new EIPs is enabled, CFW automatically synchronizes EIPs on the hour and enables protection for new EIPs. The traffic of the EIPs will be protected by the firewall.

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. (Optional) Switch to another firewall instance. Select a firewall from the drop-down list in the upper left corner of the page.
  4. In the navigation pane on the left, choose Assets > EIPs. The EIPs page is displayed.
  5. In the Firewall Information area, enable Auto Protect New EIP. In the displayed dialog box, click OK.

    Figure 2 Automatic EIP protection
    If both automatic EIP protection and multi-account protection are enabled, pay attention to the following:
    • If multi-account protection is configured before automatic EIP protection is enabled, CFW will automatically synchronize and enable Internet border traffic protection for new EIPs of all accounts (including the current account and other accounts).
    • If multi-account protection is configured or the Querying the EIP List API is called after automatic EIP protection is enabled and automatic asset synchronization is complete, you need to manually enable EIP protection for other accounts.

Follow-up Operations

Once Internet border traffic protection is enabled, your service traffic is routed through CFW. By default, all traffic is allowed. You can view traffic trends or configure access control and attack defense policies for the Internet border firewall to better control the traffic between your cloud assets and the Internet.

Related Operations

  • Disabling protection: If you do not need to protect an EIP, you can disable its protection. For details, see Disabling Protection for an EIP.

    If EIP protection is disabled, CFW no longer protects the EIP traffic, and EIPs may be exposed to attacks. Exercise caution when performing this operation.

  • Exporting the EIP list: Click Export above the list and select an export scope.
  • Multi-account protection: To protect EIPs of other accounts, see Multi-Account Management.
  • One-click kill switch and restoration: To disable or restore EIP protection under a firewall, see One-click Kill Switch and One-click Restoration.