What Is Bandwidth and How to Choose the Right One?
The bandwidth of CFW is independent of the bandwidth of other network products. Therefore, the bandwidth of CFW must be purchased separately.
Internet Firewall bandwidth: To determine the required bandwidth, first try CFW and enable the Internet Firewall Toggle for approximately seven days. Then, purchase the bandwidth based on the peak inbound/outbound traffic rates recorded in the console.
Note:
CFW offers a 7-day free trial to eligible Tencent Cloud users. Your Tencent Cloud account must meet the following requirements:
2. The root account and its sub-accounts can apply for the free trial only once in total.
NAT and CFW are independent but form a series connection. Therefore, you must select CFW bandwidth with a capacity equal to or greater than that of the NAT Gateway.
CCN and CFW are independent but form a series connection. Therefore, you must select CFW bandwidth with a capacity equal to or greater than that of CCN.
What Is Peak Bandwidth, and Is It Upstream or Downstream?
Peak bandwidth is defined as the maximum value of the inbound and outbound bandwidth. For example, when you purchase 100 Mbps bandwidth, CFW can simultaneously handle 100 Mbps inbound and 100 Mbps outbound traffic.
Will Service Bandwidth Exceeding the Internet Firewall Bandwidth Limit Affect the Service?
Bandwidth overload on the Internet Firewall does not cause packet loss or affect the traffic rate of customer services. However, the firewall will be unable to provide its protection feature.
Starting from September 25, 2024, when service bandwidth exceeds 100% of the Internet Firewall bandwidth, the following measures will be taken:
Disable some Internet Firewall Toggles to Bypass and forward a portion of the traffic, protecting only the traffic within the bandwidth specification.
The system supports configuring weights for Firewall Toggles and setting the priority for automatically disabling Firewall Toggles.
Attention:
After a Firewall Toggle is automatically disabled, you can manually enable the Internet Firewall Toggle. If service traffic exceeds the Internet Firewall bandwidth after the toggle is enabled, continue to take the measures described above.
For example:
The Internet Firewall bandwidth is 400 Mbps, with 200 Mbps allocated to the Guangzhou region. Four Internet Firewall Toggles are enabled in the Guangzhou region. When the service bandwidth in the Guangzhou region reaches 310 Mbps, two Internet Firewall Toggles are disabled. Under the protection of CFW, the service bandwidth for the Guangzhou region is maintained at 200 Mbps.
After the cooldown period, if the service bandwidth is lower than the Internet Firewall bandwidth, the Firewall Toggle is automatically re-enabled:
|
3 times or less | 2 hours |
4 to 7 times | 1 day |
8 times or more | 3 days. |
For example:
The Internet Firewall bandwidth is 600 Mbps, and five Internet Firewall Toggles are enabled. When the service bandwidth reaches 610 Mbps, one Internet Firewall Toggle is disabled, leaving only four Internet Firewall Toggles enabled. Under the protection of CFW, the service bandwidth is maintained at 600 Mbps. If the bandwidth exceeds the limit ten times within the last month, the Internet Firewall Toggles are restored three days later, and five Internet Firewall Toggles are enabled.
Continuously monitor CFW bandwidth alarms. When bandwidth is high, disable some Firewall Toggles or expand the bandwidth to ensure all traffic is protected, thereby securing your services.
Will Service Bandwidth Exceeding the NAT Firewall Bandwidth Limit Affect the Service?
The NAT Firewall operates in inline mode, and its protection bandwidth depends on the instance specification. When service bandwidth exceeds 100% of the NAT Firewall bandwidth, it can cause increased network latency or congestion and packet loss. It is recommended to monitor the Firewall bandwidth promptly based on your service conditions.
Continuously monitor CFW bandwidth alarms. When bandwidth is high, disable some Firewall Toggles or expand the bandwidth to ensure monitoring functions operate normally, thereby securing your services.
Will Service Bandwidth Exceeding the VPC Firewall Bandwidth Limit Affect the Service?
The VPC Firewall is categorized into primary/secondary mode and cluster mode. The impact of bandwidth overrun and the corresponding handling methods differ between these two modes.
Primary/Secondary Mode:
The VPC Firewall (primary/secondary mode) operates in inline mode, and its protection bandwidth depends on the instance specification. When service bandwidth exceeds 100% of the instance bandwidth, it can cause increased network latency or congestion and packet loss. It is recommended to monitor the Firewall bandwidth promptly based on your service conditions.
Cluster Mode:
When the total traffic of all CCNs connected to the Firewall under your account exceeds 100% of the VPC Firewall bandwidth, it can cause increased network latency or congestion and packet loss, potentially affecting cross-VPC communication and hybrid cloud dedicated line services.
Network latency and packet loss are automatically restored when the total traffic naturally falls back within the bandwidth limit or after the corresponding evaluation period (the specific duration is determined by the system).
Recommendations:
Enable Postpaid Elastic Traffic: Excess burst traffic is settled postpaid based on actual usage and is not subject to quota restrictions. It is recommended to set the elastic protection upper limit to be no lower than the CCN's traffic upper limit.
Scale Out and Upgrade in Advance: When daily traffic is approaching the threshold or a traffic surge is anticipated (for example, during major promotions or stress tests), it is recommended to scale out the basic protection bandwidth in advance to reserve sufficient redundancy.
Continuously monitor CFW bandwidth alarms. When bandwidth is high, disable some Firewall Toggles or expand the bandwidth to ensure all traffic is protected, thereby securing your services.
Does the CFW Internet Boundary Bandwidth Limit Traffic?
CFW does not limit traffic.
Is Inbound and Outbound Bandwidth Calculated Separately? Will Outbound Bandwidth Exceeding the Purchased Specification Affect Inbound Traffic Rule Matching?
Ingress and egress bandwidth is calculated separately.
The method for calculating the traffic peak for the Internet Firewall and the NAT Firewall is to take the maximum value of the outbound/inbound traffic.
Is the Bandwidth of the Internet Firewall and the NAT Firewall Calculated Separately?
Yes, the bandwidth for the Internet Firewall and the NAT Firewall is calculated separately.
Note:
The bandwidth of the NAT Firewall is consistent with that of the Internet Firewall. By expanding the Internet Firewall bandwidth, you can expand the NAT Firewall bandwidth.
Does CFW Bandwidth Support Arbitrary Scaling Up and Down?
Bandwidth can only be scaled out and does not support downgrading.
Does the CFW Bandwidth Limit Depend on the Bandwidth of the Connected CVM?
No. The CFW bandwidth specification sets quotas based on the bandwidth actually used by the user. This means that the traffic bandwidth consumed at any given time cannot exceed the CFW's bandwidth parameter.